Apache

Tomcat

256 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 17.02.2026 18:48:30
  • Zuletzt bearbeitet 11.03.2026 16:16:20

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known...

Exploit
  • EPSS 1.72%
  • Veröffentlicht 07.11.2025 00:00:00
  • Zuletzt bearbeitet 08.12.2025 16:10:04

In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management module, it is possible to execute any Java class with a parameterless constructor and its methods with parameter t...

  • EPSS 0.12%
  • Veröffentlicht 27.10.2025 17:30:28
  • Zuletzt bearbeitet 12.05.2026 13:17:23

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediate...

Medienbericht Exploit
  • EPSS 0.14%
  • Veröffentlicht 27.10.2025 17:29:56
  • Zuletzt bearbeitet 12.05.2026 13:17:22

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite quer...

Medienbericht
  • EPSS 0.12%
  • Veröffentlicht 27.10.2025 17:29:50
  • Zuletzt bearbeitet 12.05.2026 13:17:22

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported AN...

  • EPSS 0.02%
  • Veröffentlicht 13.08.2025 13:21:35
  • Zuletzt bearbeitet 04.11.2025 22:16:30

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are r...

  • EPSS 0.98%
  • Veröffentlicht 13.08.2025 12:11:26
  • Zuletzt bearbeitet 12.05.2026 13:17:20

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.1...

  • EPSS 1.25%
  • Veröffentlicht 10.07.2025 19:14:23
  • Zuletzt bearbeitet 04.11.2025 22:16:21

Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0....

  • EPSS 0.68%
  • Veröffentlicht 10.07.2025 19:05:41
  • Zuletzt bearbeitet 04.11.2025 22:16:20

For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.4...

Medienbericht
  • EPSS 1.21%
  • Veröffentlicht 10.07.2025 19:03:47
  • Zuletzt bearbeitet 04.11.2025 22:16:20

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This...