CVE-2026-66299
- EPSS 0.45%
- Veröffentlicht 28.07.2026 14:29:05
- Zuletzt bearbeitet 05.08.2026 18:46:21
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the secu...
CVE-2026-59084
- EPSS 0.51%
- Veröffentlicht 14.07.2026 08:24:21
- Zuletzt bearbeitet 14.07.2026 16:57:03
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 thr...
CVE-2026-59083
- EPSS 0.37%
- Veröffentlicht 14.07.2026 08:13:04
- Zuletzt bearbeitet 14.07.2026 16:57:31
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1...
CVE-2026-55957
- EPSS 2.86%
- Veröffentlicht 29.06.2026 20:47:12
- Zuletzt bearbeitet 02.07.2026 19:01:45
Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: fr...
CVE-2026-55956
- EPSS 1.53%
- Veröffentlicht 29.06.2026 20:46:02
- Zuletzt bearbeitet 02.07.2026 19:03:30
Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 throu...
CVE-2026-55955
- EPSS 0.47%
- Veröffentlicht 29.06.2026 20:44:39
- Zuletzt bearbeitet 10.07.2026 12:22:23
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 ...
CVE-2026-55276
- EPSS 0.54%
- Veröffentlicht 29.06.2026 20:42:23
- Zuletzt bearbeitet 02.07.2026 19:05:18
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 throug...
CVE-2026-53434
- EPSS 0.53%
- Veröffentlicht 29.06.2026 20:41:06
- Zuletzt bearbeitet 02.07.2026 19:06:09
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118...
CVE-2026-53404
- EPSS 0.58%
- Veröffentlicht 29.06.2026 20:39:45
- Zuletzt bearbeitet 02.07.2026 19:22:23
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through...
CVE-2026-50229
- EPSS 4.25%
- Veröffentlicht 29.06.2026 20:36:24
- Zuletzt bearbeitet 02.07.2026 19:24:34
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M...