Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 427

redhat логотип

CVE-2026-53404

около 1 месяца назад

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-50229

около 1 месяца назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.

CVSS3: 5.4
EPSS: Низкий
rocky логотип

RLSA-2026:26323

около 1 месяца назад

Important: tomcat security update

EPSS: Низкий
rocky логотип

RLSA-2026:19054

2 месяца назад

Important: tomcat security update

EPSS: Низкий
github логотип

GHSA-fv25-8xcx-gqjc

3 месяца назад

Apache Tomcat - WebSocket authentication header exposure

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-5m62-pw8w-7w9f

3 месяца назад

Apache Tomcat - Security constraints not correctly applied

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-r29c-68gh-xp6x

3 месяца назад

Apache Tomcat - HTTP/2 request headers not validated

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-gx5v-xp9w-j4cg

3 месяца назад

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-h6fc-48rj-7qqh

3 месяца назад

Apache Tomcat - Digest authenticator will authenticate any unknown user

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-5mp6-jrq3-r938

3 месяца назад

Apache Tomcat: LockOutRealm treats user names as case-sensitive

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2026-53404

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.

CVSS3: 6.5
1%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-50229

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.

CVSS3: 5.4
4%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:26323

Important: tomcat security update

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:19054

Important: tomcat security update

0%
Низкий
2 месяца назад
github логотип
GHSA-fv25-8xcx-gqjc

Apache Tomcat - WebSocket authentication header exposure

CVSS3: 7.3
1%
Низкий
3 месяца назад
github логотип
GHSA-5m62-pw8w-7w9f

Apache Tomcat - Security constraints not correctly applied

CVSS3: 9.1
1%
Низкий
3 месяца назад
github логотип
GHSA-r29c-68gh-xp6x

Apache Tomcat - HTTP/2 request headers not validated

CVSS3: 9.8
2%
Низкий
3 месяца назад
github логотип
GHSA-gx5v-xp9w-j4cg

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-h6fc-48rj-7qqh

Apache Tomcat - Digest authenticator will authenticate any unknown user

CVSS3: 9.8
1%
Низкий
3 месяца назад
github логотип
GHSA-5mp6-jrq3-r938

Apache Tomcat: LockOutRealm treats user names as case-sensitive

CVSS3: 7.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу


Поделиться