Apache Tomcat是美国阿帕奇(Apache)基金会的一款轻量级Web应用服务器。用于实现对Servlet和JavaServer Page(JSP)的支持。 Apache Tomcat 11.0.14及之前版本、10.1.49及之前版本和9.0.112及之前版本存在输入验证错误漏洞,该漏洞源于未限制HTTP/0.9请求为GET方法,可能导致绕过针对GET请求的安全约束。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M1 ~ 11.0.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-24734 | Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass | |
| CVE-2025-66614 | Apache Tomcat: Client certificate verification bypass due to virtual host mapping | |
| CVE-2026-25087 | Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering | |
| CVE-2026-25903 | Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates |
No comments yet