Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. U
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat Native | 2.0.0 ~ 2.0.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-31377 | 7.5 HIGH | Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service |
| CVE-2026-75973 | Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured | |
| CVE-2026-82331 | Apache BuildStream: tar source extraction escape | |
| CVE-2026-73192 | Apache Sling XSS: XSS possible through XSSAPI.getValidHref() | |
| CVE-2026-92001 | Apache Sling XSS: Missing parser resource limits | |
| CVE-2026-91999 | Apache Sling XSS: Improper escaping in the XSS Webconsole plugin | |
| CVE-2026-91852 | Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl | |
| CVE-2026-96443 | Apache Doris: JDBC driver URL validation bypass leads to remote code execution | |
| CVE-2026-91928 | Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf prote | |
| CVE-2026-94251 | Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape | |
| CVE-2026-94243 | Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence | |
| CVE-2026-73581 | Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate us | |
| CVE-2026-86246 | Apache Tomcat Native: Insecure OpenSSL options enabled | |
| CVE-2026-76183 | Apache Tomcat: Bypass of security constraints for WebSocket endpoints | |
| CVE-2026-77756 | Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests | |
| CVE-2026-77762 | Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request | |
| CVE-2026-77791 | Apache Tomcat: DoS via busy wait during WebSocket close | |
| CVE-2026-78383 | Apache Tomcat: AJP DoS via missing request body | |
| CVE-2026-78437 | Apache Tomcat: HTTP/2 DoS via malformed request | |
| CVE-2026-79677 | Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet