Apache / Tomcat
274 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-73180 | Apache Tomcat: Authenticated WebSocket session survives end of HTTP session | MEDIUM | 6.8 | Aug 25, 2026 |
| CVE-2026-68763 | Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset | HIGH | 7.5 | Aug 25, 2026 |
| CVE-2026-68569 | Apache Tomcat: Principal lookup can fail open in some cases | HIGH | 8.2 | Aug 25, 2026 |
| CVE-2026-68525 | Apache Tomcat: Redirect after FORM auth may bypass method specific constraints | CRITICAL | 9.1 | Aug 25, 2026 |
| CVE-2026-66422 | Apache Tomcat: Servlet role references can bypass declarative role constraints | HIGH | 8.1 | Aug 25, 2026 |
| CVE-2026-65927 | Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control | HIGH | 8.2 | Aug 25, 2026 |
| CVE-2026-65905 | Apache Tomcat: Limited replay attack possible with DIGEST authentication | CRITICAL | 9.8 | Aug 25, 2026 |
| CVE-2026-65637 | Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete | CRITICAL | 9.8 | Aug 25, 2026 |
| CVE-2026-65183 | Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets | HIGH | 8.1 | Aug 25, 2026 |
| CVE-2026-65182 | Apache Tomcat: Bypass longest prefix security constraint | CRITICAL | 9.1 | Aug 25, 2026 |
| CVE-2026-66299 | Apache Tomcat: DoS via WebSocket chat example | HIGH | 7.5 | Jul 28, 2026 |
| CVE-2026-59084 | Apache Tomcat: EncryptInterceptor requirements not clearly documented | CRITICAL | 9.1 | Jul 14, 2026 |
| CVE-2026-59083 | Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass | CRITICAL | 9.1 | Jul 14, 2026 |
| CVE-2026-55957 | Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind | HIGH | 7.3 | Jun 29, 2026 |
| CVE-2026-55956 | Apache Tomcat: Security constraints for default servlet ignored method | MEDIUM | 6.5 | Jun 29, 2026 |
| CVE-2026-55955 | Apache Tomcat: EncryptInterceptor not protected against replay attacks | MEDIUM | 6.5 | Jun 29, 2026 |
| CVE-2026-55276 | Apache Tomcat: Logged effective web.xml is incomplete | CRITICAL | 9.1 | Jun 29, 2026 |
| CVE-2026-53434 | Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector | CRITICAL | 9.1 | Jun 29, 2026 |
| CVE-2026-53404 | Apache Tomcat: Bad ornext processing in RewriteValve | HIGH | 7.3 | Jun 29, 2026 |
| CVE-2026-50229 | Apache Tomcat: XSS in number guess example | MEDIUM | 6.1 | Jun 29, 2026 |
| CVE-2026-43515 | Apache Tomcat: Security constraints not correctly applied | CRITICAL | 9.1 | May 12, 2026 |
| CVE-2026-43514 | Apache Tomcat: AJP secret compared in non-constant time | LOW | 3.7 | May 12, 2026 |
| CVE-2026-43513 | Apache Tomcat: LockOutRealm treats user names as case-sensitive | HIGH | 7.5 | May 12, 2026 |
| CVE-2026-43512 | Apache Tomcat: Digest authenticator will authenticate any unknown user | CRITICAL | 9.8 | May 12, 2026 |
| CVE-2026-41293 | Apache Tomcat: HTTP/2 request headers not validated | CRITICAL | 9.8 | May 12, 2026 |
Showing 1 to 25 of 274 CVEs