Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Tomcat — Vulnerabilities & Security Advisories 120

All 120 CVE vulnerabilities found in Apache Tomcat, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security weaknesses for the Apache Tomcat web server, categorized by Common Weakness Enumeration (CWE) tags. It aggregates vulnerability data to provide a comprehensive overview of the security posture associated with this specific product implementation. The collection includes details on various vulnerability types affecting the application server, such as remote code execution, cross-site scripting, and information disclosure flaws. This resource covers vulnerabilities disclosed from the initial release of the software up to the present day, ensuring that both legacy and modern instances are accounted for in the analysis. Readers can use this aggregated view to track vendor advisories issued by the Apache Software Foundation, understand the prevalence and impact of specific weakness classes within the Tomcat ecosystem, and look up the historical vulnerability profile of the product to assess risk exposure. By centralizing these data points, the page serves as a reference for security professionals and system administrators seeking to evaluate the integrity of their deployments. The information is organized to facilitate easy navigation through different categories of security issues, allowing users to identify patterns or recurring themes in reported defects. This approach supports informed decision-making regarding patching strategies and configuration hardening without requiring users to manually sift through numerous individual reports.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2026-66299 Apache Tomcat: DoS via WebSocket chat example CWE-400--2026-07-28
CVE-2026-59084 Apache Tomcat: EncryptInterceptor requirements not clearly documented CWE-1059--2026-07-14
CVE-2026-59083 Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass CWE-177--2026-07-14
CVE-2026-55957 Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind CWE-304--2026-06-29
CVE-2026-55956 Apache Tomcat: Security constraints for default servlet ignored method CWE-285--2026-06-29
CVE-2026-55955 Apache Tomcat: EncryptInterceptor not protected against replay attacks CWE-287--2026-06-29
CVE-2026-55276 Apache Tomcat: Logged effective web.xml is incomplete CWE-670--2026-06-29
CVE-2026-53434 Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector CWE-390--2026-06-29
CVE-2026-53404 Apache Tomcat: Bad ornext processing in RewriteValve CWE-670--2026-06-29
CVE-2026-50229 Apache Tomcat: XSS in number guess example CWE-80--2026-06-29
CVE-2026-43515 Apache Tomcat: Security constraints not correctly applied CWE-285--2026-05-12
CVE-2026-43514 Apache Tomcat: AJP secret compared in non-constant time CWE-208--2026-05-12
CVE-2026-43513 Apache Tomcat: LockOutRealm treats user names as case-sensitive CWE-178--2026-05-12
CVE-2026-43512 Apache Tomcat: Digest authenticator will authenticate any unknown user CWE-592--2026-05-12
CVE-2026-41293 Apache Tomcat: HTTP/2 request headers not validated CWE-20--2026-05-12
CVE-2026-42498 Apache Tomcat: WebSocket authentication header exposure CWE-200--2026-05-12
CVE-2026-41284 Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling CWE-770--2026-05-12
CVE-2026-34500 Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled 8.1AIHighAI2026-04-09
CVE-2026-34487 Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token CWE-532 7.5AIHighAI2026-04-09
CVE-2026-34486 Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor CWE-311 7.5AIHighAI2026-04-09
CVE-2026-34483 Apache Tomcat: Incomplete escaping of JSON access logs CWE-116 9.8AICriticalAI2026-04-09
CVE-2026-32990 Apache Tomcat: Fix for CVE-2025-66614 is incomplete CWE-20 9.1AICriticalAI2026-04-09
CVE-2026-29146 Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default 9.1AICriticalAI2026-04-09
CVE-2026-29145 Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled 9.8AICriticalAI2026-04-09
CVE-2026-29129 Apache Tomcat: TLS cipher order is not preserved 7.5AIHighAI2026-04-09
CVE-2026-25854 Apache Tomcat: Occasionally open redirect CWE-601 6.1AIMediumAI2026-04-09
CVE-2026-24880 Apache Tomcat: Request smuggling via invalid chunk extension CWE-444 9.1AICriticalAI2026-04-09
CVE-2026-24733 Apache Tomcat: Security constraint bypass with HTTP/0.9 CWE-20 7.5AIHighAI2026-02-17
CVE-2025-66614 Apache Tomcat: Client certificate verification bypass due to virtual host mapping CWE-20 9.8AICriticalAI2026-02-17
CVE-2025-61795 Apache Tomcat: Delayed cleaning of multi-part upload temporary files may lead to DoS CWE-404 7.5 -2025-10-27

All 120 known CVE vulnerabilities affecting Apache Tomcat with full Chinese analysis, references, and POCs where available.