Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 18

Количество 18

ubuntu логотип

CVE-2026-73180

30 дней назад

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2026-73180

30 дней назад

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-73180

30 дней назад

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2026-73180

30 дней назад

Insufficient Session Expiration vulnerability in Apache Tomcat meant t ...

CVSS3: 6.8
EPSS: Низкий
redos логотип

ROS-20260922-80-0079

3 дня назад

Уязвимость tomcat11

CVSS3: 6.8
EPSS: Низкий
redos логотип

ROS-20260922-80-0078

3 дня назад

Уязвимость tomcat10

CVSS3: 6.8
EPSS: Низкий
redos логотип

ROS-20260922-73-0055

3 дня назад

Уязвимость tomcat11

CVSS3: 6.8
EPSS: Низкий
redos логотип

ROS-20260922-73-0054

3 дня назад

Уязвимость tomcat10

CVSS3: 6.8
EPSS: Низкий
redos логотип

ROS-20260907-80-0100

18 дней назад

Уязвимость tomcat

CVSS3: 6.8
EPSS: Низкий
redos логотип

ROS-20260907-73-0069

18 дней назад

Уязвимость tomcat

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-wrvx-pxxf-g8fg

30 дней назад

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 6.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4203-1

8 дней назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4126-1

13 дней назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4119-1

14 дней назад

Security update for tomcat10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4114-1

15 дней назад

Security update for tomcat11

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21823-1

15 дней назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21811-1

16 дней назад

Security update for tomcat11

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21810-1

16 дней назад

Security update for tomcat10

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-73180

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 6.8
1%
Низкий
30 дней назад
redhat логотип
CVE-2026-73180

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 5.4
1%
Низкий
30 дней назад
nvd логотип
CVE-2026-73180

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 6.8
1%
Низкий
30 дней назад
debian логотип
CVE-2026-73180

Insufficient Session Expiration vulnerability in Apache Tomcat meant t ...

CVSS3: 6.8
1%
Низкий
30 дней назад
redos логотип
ROS-20260922-80-0079

Уязвимость tomcat11

CVSS3: 6.8
1%
Низкий
3 дня назад
redos логотип
ROS-20260922-80-0078

Уязвимость tomcat10

CVSS3: 6.8
1%
Низкий
3 дня назад
redos логотип
ROS-20260922-73-0055

Уязвимость tomcat11

CVSS3: 6.8
1%
Низкий
3 дня назад
redos логотип
ROS-20260922-73-0054

Уязвимость tomcat10

CVSS3: 6.8
1%
Низкий
3 дня назад
redos логотип
ROS-20260907-80-0100

Уязвимость tomcat

CVSS3: 6.8
1%
Низкий
18 дней назад
redos логотип
ROS-20260907-73-0069

Уязвимость tomcat

CVSS3: 6.8
1%
Низкий
18 дней назад
github логотип
GHSA-wrvx-pxxf-g8fg

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 6.8
1%
Низкий
30 дней назад
suse-cvrf логотип
SUSE-SU-2026:4203-1

Security update for tomcat

8 дней назад
suse-cvrf логотип
SUSE-SU-2026:4126-1

Security update for tomcat

13 дней назад
suse-cvrf логотип
SUSE-SU-2026:4119-1

Security update for tomcat10

14 дней назад
suse-cvrf логотип
SUSE-SU-2026:4114-1

Security update for tomcat11

15 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21823-1

Security update for tomcat

15 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21811-1

Security update for tomcat11

16 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21810-1

Security update for tomcat10

16 дней назад

Уязвимостей на страницу