Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 18

Количество 18

ubuntu логотип

CVE-2026-24733

5 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2026-24733

5 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-24733

5 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2026-24733

5 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did ...

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0922-1

4 месяца назад

Security update for tomcat

EPSS: Низкий
github логотип

GHSA-qq5r-98hh-rxc9

5 месяцев назад

Apache Tomcat - Security constraint bypass with HTTP/0.9

EPSS: Низкий
fstec логотип

BDU:2026-05102

5 месяцев назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260506-73-0017

3 месяца назад

Уязвимость tomcat11

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260506-73-0016

3 месяца назад

Уязвимость tomcat10

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260506-73-0015

3 месяца назад

Уязвимость tomcat

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20414-1

4 месяца назад

Security update for tomcat11

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20350-1

5 месяцев назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0932-1

4 месяца назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0890-1

5 месяцев назад

Security update for tomcat10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0877-1

5 месяцев назад

Security update for tomcat11

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20444-1

4 месяца назад

Security update for tomcat10

EPSS: Низкий
rocky логотип

RLSA-2026:36790

21 день назад

Important: tomcat9 security, bug fix, and enhancement update

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1058-1

4 месяца назад

Security update for tomcat

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-24733

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 3.7
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-24733

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-24733

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 3.7
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-24733

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did ...

CVSS3: 3.7
0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0922-1

Security update for tomcat

0%
Низкий
4 месяца назад
github логотип
GHSA-qq5r-98hh-rxc9

Apache Tomcat - Security constraint bypass with HTTP/0.9

0%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-05102

Уязвимость сервера приложений Apache Tomcat, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.5
0%
Низкий
5 месяцев назад
redos логотип
ROS-20260506-73-0017

Уязвимость tomcat11

CVSS3: 6.5
0%
Низкий
3 месяца назад
redos логотип
ROS-20260506-73-0016

Уязвимость tomcat10

CVSS3: 6.5
0%
Низкий
3 месяца назад
redos логотип
ROS-20260506-73-0015

Уязвимость tomcat

CVSS3: 6.5
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20414-1

Security update for tomcat11

4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20350-1

Security update for tomcat

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0932-1

Security update for tomcat

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0890-1

Security update for tomcat10

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0877-1

Security update for tomcat11

5 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20444-1

Security update for tomcat10

4 месяца назад
rocky логотип
RLSA-2026:36790

Important: tomcat9 security, bug fix, and enhancement update

21 день назад
suse-cvrf логотип
SUSE-SU-2026:1058-1

Security update for tomcat

4 месяца назад

Уязвимостей на страницу