Apache Software Foundation Apache Tomcat是Apache Software Foundation基金会的应用服务器。 Apache Tomcat存在处理逻辑错误漏洞,该漏洞源于Always-Incorrect Control Flow Implementation,导致记录有效web.xml时未包含特殊角色和空授权约束。以下版本受到影响:11.0.0-M1版本至11.0.22版本、10.1.0-M1版本至10.1.55版本、9.0.0.M1版本至9.0.118版本和8
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M1≤ 11.0.22 |
affected |
10.1.0-M1≤ 10.1.55 |
affected | ||
9.0.0.M1≤ 9.0.118 |
affected | ||
8.5.0≤ 8.5.100 |
affected | ||
< 8.0.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M1 ~ 11.0.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55957 | Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind | |
| CVE-2026-55956 | Apache Tomcat: Security constraints for default servlet ignored method | |
| CVE-2026-55955 | Apache Tomcat: EncryptInterceptor not protected against replay attacks | |
| CVE-2026-53434 | Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector | |
| CVE-2026-53404 | Apache Tomcat: Bad ornext processing in RewriteValve | |
| CVE-2026-50229 | Apache Tomcat: XSS in number guess example |
No comments yet