Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 427

github логотип

GHSA-95jq-rwvf-vjx4

4 месяца назад

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-563x-q5rq-57qp

4 месяца назад

Apache Tomcat has an HTTP Request/Response Smuggling vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-h468-7pvh-8vr8

4 месяца назад

Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-69cc-cv78-qc8g

4 месяца назад

Apache Tomcat: Configured cipher preference order not preserved

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8mc5-53m5-3qj2

4 месяца назад

Apache Tomcat has an Improper Input Validation vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9m3c-qcxr-9x87

4 месяца назад

Apache Tomcat has an Open Redirect vulnerability

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-34500

4 месяца назад

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-34500

4 месяца назад

CLIENT_CERT authentication does not fail as expected for some scenario ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-34487

4 месяца назад

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-34487

4 месяца назад

Insertion of Sensitive Information into Log File vulnerability in the ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-95jq-rwvf-vjx4

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

CVSS3: 9.1
1%
Низкий
4 месяца назад
github логотип
GHSA-563x-q5rq-57qp

Apache Tomcat has an HTTP Request/Response Smuggling vulnerability

CVSS3: 7.5
1%
Низкий
4 месяца назад
github логотип
GHSA-h468-7pvh-8vr8

Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor

CVSS3: 7.5
6%
Низкий
4 месяца назад
github логотип
GHSA-69cc-cv78-qc8g

Apache Tomcat: Configured cipher preference order not preserved

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-8mc5-53m5-3qj2

Apache Tomcat has an Improper Input Validation vulnerability

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-9m3c-qcxr-9x87

Apache Tomcat has an Open Redirect vulnerability

CVSS3: 6.1
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-34500

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

CVSS3: 6.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-34500

CLIENT_CERT authentication does not fail as expected for some scenario ...

CVSS3: 6.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-34487

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-34487

Insertion of Sensitive Information into Log File vulnerability in the ...

CVSS3: 7.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу


Поделиться