Tomcat — контейнер сервлетов с открытым исходным кодом
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 427
GHSA-95jq-rwvf-vjx4
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
GHSA-563x-q5rq-57qp
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
GHSA-h468-7pvh-8vr8
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
GHSA-69cc-cv78-qc8g
Apache Tomcat: Configured cipher preference order not preserved
GHSA-8mc5-53m5-3qj2
Apache Tomcat has an Improper Input Validation vulnerability
GHSA-9m3c-qcxr-9x87
Apache Tomcat has an Open Redirect vulnerability
CVE-2026-34500
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.
CVE-2026-34500
CLIENT_CERT authentication does not fail as expected for some scenario ...
CVE-2026-34487
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
CVE-2026-34487
Insertion of Sensitive Information into Log File vulnerability in the ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-95jq-rwvf-vjx4 Apache Tomcat: CLIENT_CERT authentication does not fail as expected | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
GHSA-563x-q5rq-57qp Apache Tomcat has an HTTP Request/Response Smuggling vulnerability | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
GHSA-h468-7pvh-8vr8 Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor | CVSS3: 7.5 | 6% Низкий | 4 месяца назад | |
GHSA-69cc-cv78-qc8g Apache Tomcat: Configured cipher preference order not preserved | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
GHSA-8mc5-53m5-3qj2 Apache Tomcat has an Improper Input Validation vulnerability | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
GHSA-9m3c-qcxr-9x87 Apache Tomcat has an Open Redirect vulnerability | CVSS3: 6.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-34500 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-34500 CLIENT_CERT authentication does not fail as expected for some scenario ... | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-34487 Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-34487 Insertion of Sensitive Information into Log File vulnerability in the ... | CVSS3: 7.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу