Apache / Apache Tomcat
138 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-87022 | Apache Tomcat: WebSocket message smuggling with per-message-deflate | HIGH | 7.5 | Sep 23, 2026 |
| CVE-2026-86350 | Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up | CRITICAL | 9.1 | Sep 23, 2026 |
| CVE-2026-86248 | Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled | CRITICAL | 9.8 | Sep 23, 2026 |
| CVE-2026-79677 | Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout | HIGH | 7.5 | Sep 23, 2026 |
| CVE-2026-78437 | Apache Tomcat: HTTP/2 DoS via malformed request | HIGH | 7.3 | Sep 23, 2026 |
| CVE-2026-78383 | Apache Tomcat: AJP DoS via missing request body | HIGH | 7.5 | Sep 23, 2026 |
| CVE-2026-77791 | Apache Tomcat: DoS via busy wait during WebSocket close | HIGH | 7.5 | Sep 23, 2026 |
| CVE-2026-77762 | Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request | HIGH | 8.1 | Sep 23, 2026 |
| CVE-2026-77756 | Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests | LOW | 3.7 | Sep 23, 2026 |
| CVE-2026-76183 | Apache Tomcat: Bypass of security constraints for WebSocket endpoints | CRITICAL | 9.8 | Sep 23, 2026 |
| CVE-2026-75973 | Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured | HIGH | 7.3 | Sep 23, 2026 |
| CVE-2026-73581 | Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore | MEDIUM | 6.5 | Sep 23, 2026 |
| CVE-2026-73180 | Apache Tomcat: Authenticated WebSocket session survives end of HTTP session | MEDIUM | 6.8 | Aug 25, 2026 |
| CVE-2026-68763 | Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset | HIGH | 7.5 | Aug 25, 2026 |
| CVE-2026-68569 | Apache Tomcat: Principal lookup can fail open in some cases | HIGH | 8.2 | Aug 25, 2026 |
| CVE-2026-68525 | Apache Tomcat: Redirect after FORM auth may bypass method specific constraints | CRITICAL | 9.1 | Aug 25, 2026 |
| CVE-2026-66422 | Apache Tomcat: Servlet role references can bypass declarative role constraints | HIGH | 8.1 | Aug 25, 2026 |
| CVE-2026-65927 | Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control | HIGH | 8.2 | Aug 25, 2026 |
| CVE-2026-65905 | Apache Tomcat: Limited replay attack possible with DIGEST authentication | CRITICAL | 9.8 | Aug 25, 2026 |
| CVE-2026-65637 | Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete | CRITICAL | 9.8 | Aug 25, 2026 |
| CVE-2026-65183 | Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets | HIGH | 8.1 | Aug 25, 2026 |
| CVE-2026-65182 | Apache Tomcat: Bypass longest prefix security constraint | CRITICAL | 9.1 | Aug 25, 2026 |
| CVE-2026-66299 | Apache Tomcat: DoS via WebSocket chat example | HIGH | 7.5 | Jul 28, 2026 |
| CVE-2026-59084 | Apache Tomcat: EncryptInterceptor requirements not clearly documented | CRITICAL | 9.1 | Jul 14, 2026 |
| CVE-2026-59083 | Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass | CRITICAL | 9.1 | Jul 14, 2026 |
Showing 1 to 25 of 138 CVEs