Apache Tomcat和Apache Tomcat Native都是美国阿帕奇(Apache)基金会的产品。Apache Tomcat是一款轻量级Web应用服务器。用于实现对Servlet和JavaServer Page(JSP)的支持。Apache Tomcat Native是一个本地组件库。 Apache Tomcat Native 1.3.4及之前版本、2.0.11及之前版本和Apache Tomcat 11.0.17及之前版本、10.1.51及之前版本、9.0.114及之前版本存在输入验证错误
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M1≤ 11.0.17 |
affected |
10.1.0-M7≤ 10.1.51 |
affected | ||
9.0.83≤ 9.0.114 |
affected | ||
≤ 8.5.100 |
unaffected | ||
| Apache Software Foundation | Apache Tomcat Native | 1.1.23≤ 1.1.34 |
affected |
1.2.0≤ 1.2.39 |
affected | ||
1.3.0≤ 1.3.4 |
affected | ||
2.0.0≤ 2.0.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat Native | 1.1.23 ~ 1.1.34 | - |
|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M1 ~ 11.0.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-24733 | Apache Tomcat: Security constraint bypass with HTTP/0.9 | |
| CVE-2025-66614 | Apache Tomcat: Client certificate verification bypass due to virtual host mapping | |
| CVE-2026-25087 | Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering | |
| CVE-2026-25903 | Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates |
No comments yet