Количество 17
Количество 17
BDU:2026-06932
Уязвимость сервера приложений Apache Tomcat, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling)
ROS-20260506-73-0026
Уязвимость tomcat11
ROS-20260506-73-0025
Уязвимость tomcat10
ROS-20260506-73-0024
Уязвимость tomcat
CVE-2026-24880
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.
CVE-2026-24880
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.
CVE-2026-24880
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.
CVE-2026-24880
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...
GHSA-563x-q5rq-57qp
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
openSUSE-SU-2026:20612-1
Security update for tomcat10
openSUSE-SU-2026:20611-1
Security update for tomcat
openSUSE-SU-2026:20595-1
Security update for tomcat11
SUSE-SU-2026:1604-1
Security update for tomcat
SUSE-SU-2026:1603-1
Security update for tomcat10
SUSE-SU-2026:1572-1
Security update for tomcat
SUSE-SU-2026:1558-1
Security update for tomcat11
RLSA-2026:36790
Important: tomcat9 security, bug fix, and enhancement update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-06932 Уязвимость сервера приложений Apache Tomcat, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling) | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
ROS-20260506-73-0026 Уязвимость tomcat11 | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
ROS-20260506-73-0025 Уязвимость tomcat10 | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
ROS-20260506-73-0024 Уязвимость tomcat | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-24880 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-24880 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue. | CVSS3: 4.3 | 1% Низкий | 4 месяца назад | |
CVE-2026-24880 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-24880 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ... | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
GHSA-563x-q5rq-57qp Apache Tomcat has an HTTP Request/Response Smuggling vulnerability | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
openSUSE-SU-2026:20612-1 Security update for tomcat10 | 3 месяца назад | |||
openSUSE-SU-2026:20611-1 Security update for tomcat | 3 месяца назад | |||
openSUSE-SU-2026:20595-1 Security update for tomcat11 | 3 месяца назад | |||
SUSE-SU-2026:1604-1 Security update for tomcat | 3 месяца назад | |||
SUSE-SU-2026:1603-1 Security update for tomcat10 | 3 месяца назад | |||
SUSE-SU-2026:1572-1 Security update for tomcat | 3 месяца назад | |||
SUSE-SU-2026:1558-1 Security update for tomcat11 | 3 месяца назад | |||
RLSA-2026:36790 Important: tomcat9 security, bug fix, and enhancement update | 21 день назад |
Уязвимостей на страницу