Apache

Tomcat

256 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 09.04.2026 20:16:25
  • Zuletzt bearbeitet 14.04.2026 12:43:28

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through...

  • EPSS 0.24%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 20:02:48

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0...

  • EPSS 0.03%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 14:01:07

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through...

  • EPSS 0.03%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 14:00:19

Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version...

  • EPSS 0.04%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 13:22:28

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52...

Medienbericht
  • EPSS 9.94%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 12:56:21

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100,...

  • EPSS 0.21%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 12:47:51

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended t...

  • EPSS 0.09%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 12:46:39

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are rec...

Medienbericht
  • EPSS 0.09%
  • Veröffentlicht 17.02.2026 18:53:12
  • Zuletzt bearbeitet 11.03.2026 16:16:29

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response whic...

  • EPSS 0.16%
  • Veröffentlicht 17.02.2026 18:50:43
  • Zuletzt bearbeitet 11.03.2026 16:16:29

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constrai...