Tomcat — контейнер сервлетов с открытым исходным кодом
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 427
CVE-2026-53404
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
CVE-2026-50229
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
RLSA-2026:26323
Important: tomcat security update
RLSA-2026:19054
Important: tomcat security update
GHSA-fv25-8xcx-gqjc
Apache Tomcat - WebSocket authentication header exposure
GHSA-5m62-pw8w-7w9f
Apache Tomcat - Security constraints not correctly applied
GHSA-r29c-68gh-xp6x
Apache Tomcat - HTTP/2 request headers not validated
GHSA-gx5v-xp9w-j4cg
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
GHSA-h6fc-48rj-7qqh
Apache Tomcat - Digest authenticator will authenticate any unknown user
GHSA-5mp6-jrq3-r938
Apache Tomcat: LockOutRealm treats user names as case-sensitive
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2026-53404 Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue. | CVSS3: 6.5 | 1% Низкий | около 1 месяца назад | |
CVE-2026-50229 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue. | CVSS3: 5.4 | 4% Низкий | около 1 месяца назад | |
RLSA-2026:26323 Important: tomcat security update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:19054 Important: tomcat security update | 0% Низкий | 2 месяца назад | ||
GHSA-fv25-8xcx-gqjc Apache Tomcat - WebSocket authentication header exposure | CVSS3: 7.3 | 1% Низкий | 3 месяца назад | |
GHSA-5m62-pw8w-7w9f Apache Tomcat - Security constraints not correctly applied | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
GHSA-r29c-68gh-xp6x Apache Tomcat - HTTP/2 request headers not validated | CVSS3: 9.8 | 2% Низкий | 3 месяца назад | |
GHSA-gx5v-xp9w-j4cg Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
GHSA-h6fc-48rj-7qqh Apache Tomcat - Digest authenticator will authenticate any unknown user | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
GHSA-5mp6-jrq3-r938 Apache Tomcat: LockOutRealm treats user names as case-sensitive | CVSS3: 7.5 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу