Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 533

debian логотип

CVE-2026-34486

5 месяцев назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat du ...

CVSS3: 7.5
EPSS: Критический
nvd логотип

CVE-2026-34486

5 месяцев назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
EPSS: Критический
debian логотип

CVE-2026-34483

5 месяцев назад

Improper Encoding or Escaping of Output vulnerability in the JsonAcces ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-34483

5 месяцев назад

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-32990

5 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat due to an inc ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-32990

5 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-29146

5 месяцев назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor wit ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-29146

5 месяцев назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-29145

5 месяцев назад

CLIENT_CERT authentication does not fail as expected for some scenario ...

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-29145

5 месяцев назад

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2026-34486

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat du ...

CVSS3: 7.5
99%
Критический
5 месяцев назад
nvd логотип
CVE-2026-34486

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
99%
Критический
5 месяцев назад
debian логотип
CVE-2026-34483

Improper Encoding or Escaping of Output vulnerability in the JsonAcces ...

CVSS3: 7.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-34483

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-32990

Improper Input Validation vulnerability in Apache Tomcat due to an inc ...

CVSS3: 5.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-32990

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-29146

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor wit ...

CVSS3: 7.5
9%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-29146

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

CVSS3: 7.5
9%
Низкий
5 месяцев назад
debian логотип
CVE-2026-29145

CLIENT_CERT authentication does not fail as expected for some scenario ...

CVSS3: 9.1
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-29145

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.

CVSS3: 9.1
1%
Низкий
5 месяцев назад

Уязвимостей на страницу


Поделиться