Количество 22
Количество 22
GHSA-mgp5-rv84-w37q
Apache Tomcat has an Improper Input Validation vulnerability
CVE-2026-24734
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.
CVE-2026-24734
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.
CVE-2026-24734
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.
CVE-2026-24734
Improper Input Validation vulnerability in Apache Tomcat Native, Apach ...
RLSA-2026:26323
Important: tomcat security update
RLSA-2026:19054
Important: tomcat security update
ELSA-2026-26323
ELSA-2026-26323: tomcat security update (IMPORTANT)
ELSA-2026-25341
ELSA-2026-25341: tomcat9 update (IMPORTANT)
ELSA-2026-19054
ELSA-2026-19054: tomcat security update (IMPORTANT)
BDU:2026-05104
Уязвимость компонента OCSP сервера приложений Apache Tomcat, позволяющая нарушителю выполнить произвольный код
ROS-20260506-73-0014
Уязвимость tomcat-native
ROS-20260506-73-0013
Уязвимость tomcat11
ROS-20260506-73-0012
Уязвимость tomcat
ROS-20260506-73-0011
Уязвимость tomcat10
openSUSE-SU-2026:20414-1
Security update for tomcat11
openSUSE-SU-2026:20350-1
Security update for tomcat
SUSE-SU-2026:0932-1
Security update for tomcat
SUSE-SU-2026:0890-1
Security update for tomcat10
SUSE-SU-2026:0877-1
Security update for tomcat11
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-mgp5-rv84-w37q Apache Tomcat has an Improper Input Validation vulnerability | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-24734 Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-24734 Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue. | CVSS3: 7.4 | 0% Низкий | 5 месяцев назад | |
CVE-2026-24734 Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-24734 Improper Input Validation vulnerability in Apache Tomcat Native, Apach ... | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
RLSA-2026:26323 Important: tomcat security update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:19054 Important: tomcat security update | 0% Низкий | 2 месяца назад | ||
ELSA-2026-26323 ELSA-2026-26323: tomcat security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-25341 ELSA-2026-25341: tomcat9 update (IMPORTANT) | 8 дней назад | |||
ELSA-2026-19054 ELSA-2026-19054: tomcat security update (IMPORTANT) | 23 дня назад | |||
BDU:2026-05104 Уязвимость компонента OCSP сервера приложений Apache Tomcat, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
ROS-20260506-73-0014 Уязвимость tomcat-native | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
ROS-20260506-73-0013 Уязвимость tomcat11 | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
ROS-20260506-73-0012 Уязвимость tomcat | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
ROS-20260506-73-0011 Уязвимость tomcat10 | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:20414-1 Security update for tomcat11 | 4 месяца назад | |||
openSUSE-SU-2026:20350-1 Security update for tomcat | 5 месяцев назад | |||
SUSE-SU-2026:0932-1 Security update for tomcat | 4 месяца назад | |||
SUSE-SU-2026:0890-1 Security update for tomcat10 | 5 месяцев назад | |||
SUSE-SU-2026:0877-1 Security update for tomcat11 | 5 месяцев назад |
Уязвимостей на страницу