CVE-2025-31650
- EPSS 4.54%
- Published 28.04.2025 19:14:31
- Last modified 08.08.2025 12:15:27
Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger...
CVE-2025-24813
- EPSS 94.18%
- Published 10.03.2025 16:44:03
- Last modified 08.08.2025 17:56:59
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 1...
CVE-2024-56337
- EPSS 28.59%
- Published 20.12.2024 16:15:24
- Last modified 08.08.2025 12:15:27
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the t...
CVE-2024-50379
- EPSS 88.19%
- Published 17.12.2024 13:15:18
- Last modified 08.08.2025 12:15:25
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apa...
CVE-2024-54677
- EPSS 7.24%
- Published 17.12.2024 13:15:18
- Last modified 08.08.2025 12:15:27
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 th...
CVE-2024-52318
- EPSS 3.66%
- Published 18.11.2024 13:15:04
- Last modified 15.05.2025 17:46:50
Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.
CVE-2024-52316
- EPSS 0.99%
- Published 18.11.2024 12:15:18
- Last modified 08.08.2025 12:15:26
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly s...
CVE-2024-52317
- EPSS 6.95%
- Published 18.11.2024 12:15:18
- Last modified 15.05.2025 17:51:16
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0...
CVE-2024-38286
- EPSS 1.36%
- Published 07.11.2024 08:15:13
- Last modified 08.08.2025 11:15:28
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL a...
CVE-2024-34750
- EPSS 16.9%
- Published 03.07.2024 20:15:04
- Last modified 08.08.2025 11:15:27
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active...