Количество 18
Количество 18
BDU:2026-05102
Уязвимость сервера приложений Apache Tomcat, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код
ROS-20260506-73-0017
Уязвимость tomcat11
ROS-20260506-73-0016
Уязвимость tomcat10
ROS-20260506-73-0015
Уязвимость tomcat
CVE-2026-24733
Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
CVE-2026-24733
Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
CVE-2026-24733
Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
CVE-2026-24733
Improper Input Validation vulnerability in Apache Tomcat. Tomcat did ...
SUSE-SU-2026:0922-1
Security update for tomcat
GHSA-qq5r-98hh-rxc9
Apache Tomcat - Security constraint bypass with HTTP/0.9
openSUSE-SU-2026:20414-1
Security update for tomcat11
openSUSE-SU-2026:20350-1
Security update for tomcat
SUSE-SU-2026:0932-1
Security update for tomcat
SUSE-SU-2026:0890-1
Security update for tomcat10
SUSE-SU-2026:0877-1
Security update for tomcat11
openSUSE-SU-2026:20444-1
Security update for tomcat10
RLSA-2026:36790
Important: tomcat9 security, bug fix, and enhancement update
SUSE-SU-2026:1058-1
Security update for tomcat
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-05102 Уязвимость сервера приложений Apache Tomcat, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
ROS-20260506-73-0017 Уязвимость tomcat11 | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
ROS-20260506-73-0016 Уязвимость tomcat10 | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
ROS-20260506-73-0015 Уязвимость tomcat | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-24733 Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue. | CVSS3: 3.7 | 0% Низкий | 5 месяцев назад | |
CVE-2026-24733 Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue. | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
CVE-2026-24733 Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue. | CVSS3: 3.7 | 0% Низкий | 5 месяцев назад | |
CVE-2026-24733 Improper Input Validation vulnerability in Apache Tomcat. Tomcat did ... | CVSS3: 3.7 | 0% Низкий | 5 месяцев назад | |
SUSE-SU-2026:0922-1 Security update for tomcat | 0% Низкий | 4 месяца назад | ||
GHSA-qq5r-98hh-rxc9 Apache Tomcat - Security constraint bypass with HTTP/0.9 | 0% Низкий | 5 месяцев назад | ||
openSUSE-SU-2026:20414-1 Security update for tomcat11 | 4 месяца назад | |||
openSUSE-SU-2026:20350-1 Security update for tomcat | 5 месяцев назад | |||
SUSE-SU-2026:0932-1 Security update for tomcat | 4 месяца назад | |||
SUSE-SU-2026:0890-1 Security update for tomcat10 | 5 месяцев назад | |||
SUSE-SU-2026:0877-1 Security update for tomcat11 | 5 месяцев назад | |||
openSUSE-SU-2026:20444-1 Security update for tomcat10 | 4 месяца назад | |||
RLSA-2026:36790 Important: tomcat9 security, bug fix, and enhancement update | 21 день назад | |||
SUSE-SU-2026:1058-1 Security update for tomcat | 4 месяца назад |
Уязвимостей на страницу