Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache Tomcat — Vulnerabilities & Security Advisories 142

All 142 CVE vulnerabilities found in Apache Tomcat, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Apache Tomcat, a Java web server and servlet container developed by the Apache Software Foundation. It collects security advisories and known weaknesses associated with this product, covering disclosures spanning its release history. Readers can use this resource to track vendor-issued security notices, analyze specific weakness classes affecting Tomcat, and review the product's historical vulnerability profile to assess risk trends over time.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-87022 Apache Tomcat: WebSocket message smuggling with per-message-deflate CWE-130 - - 2026-09-23
CVE-2026-86350 Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up CWE-444 - - 2026-09-23
CVE-2026-86248 Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled - - 2026-09-23
CVE-2026-79677 Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout CWE-772 - - 2026-09-23
CVE-2026-78437 Apache Tomcat: HTTP/2 DoS via malformed request CWE-459 - - 2026-09-23
CVE-2026-78383 Apache Tomcat: AJP DoS via missing request body CWE-770 - - 2026-09-23
CVE-2026-77791 Apache Tomcat: DoS via busy wait during WebSocket close CWE-400 - - 2026-09-23
CVE-2026-77762 Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request CWE-362 - - 2026-09-23
CVE-2026-77756 Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests CWE-444 - - 2026-09-23
CVE-2026-76183 Apache Tomcat: Bypass of security constraints for WebSocket endpoints CWE-289 - - 2026-09-23
CVE-2026-75973 Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured CWE-287 - - 2026-09-23
CVE-2026-73581 Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore CWE-299 - - 2026-09-23
CVE-2026-73180 Apache Tomcat: Authenticated WebSocket session survives end of HTTP session CWE-613 - - 2026-08-25
CVE-2026-68763 Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset CWE-400 - - 2026-08-25
CVE-2026-68569 Apache Tomcat: Principal lookup can fail open in some cases CWE-287 - - 2026-08-25
CVE-2026-68525 Apache Tomcat: Redirect after FORM auth may bypass method specific constraints CWE-863 - - 2026-08-25
CVE-2026-66422 Apache Tomcat: Servlet role references can bypass declarative role constraints CWE-285 - - 2026-08-25
CVE-2026-65927 Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control CWE-193 - - 2026-08-25
CVE-2026-65905 Apache Tomcat: Limited replay attack possible with DIGEST authentication CWE-294 - - 2026-08-25
CVE-2026-65637 Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete CWE-20 - - 2026-08-25
CVE-2026-65183 Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets CWE-367 - - 2026-08-25
CVE-2026-65182 Apache Tomcat: Bypass longest prefix security constraint CWE-284 - - 2026-08-25
CVE-2026-66299 Apache Tomcat: DoS via WebSocket chat example CWE-400 - - 2026-07-28
CVE-2026-59084 Apache Tomcat: EncryptInterceptor requirements not clearly documented CWE-1059 - - 2026-07-14
CVE-2026-59083 Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass CWE-177 - - 2026-07-14
CVE-2026-55957 Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind CWE-304 - - 2026-06-29
CVE-2026-55956 Apache Tomcat: Security constraints for default servlet ignored method CWE-285 - - 2026-06-29
CVE-2026-55955 Apache Tomcat: EncryptInterceptor not protected against replay attacks CWE-287 - - 2026-06-29
CVE-2026-55276 Apache Tomcat: Logged effective web.xml is incomplete CWE-670 - - 2026-06-29
CVE-2026-53434 Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector CWE-390 - - 2026-06-29

All 142 known CVE vulnerabilities affecting Apache Tomcat with full Chinese analysis, references, and POCs where available.