CVE-2026-65183
- EPSS 0.33%
- Veröffentlicht 25.08.2026 21:44:49
- Zuletzt bearbeitet 27.08.2026 15:26:04
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24...
CVE-2026-65182
- EPSS 0.46%
- Veröffentlicht 25.08.2026 21:43:37
- Zuletzt bearbeitet 27.08.2026 15:27:26
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apac...
CVE-2026-66299
- EPSS 0.45%
- Veröffentlicht 28.07.2026 14:29:05
- Zuletzt bearbeitet 27.08.2026 16:24:41
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the secu...
CVE-2026-59084
- EPSS 0.51%
- Veröffentlicht 14.07.2026 08:24:21
- Zuletzt bearbeitet 14.07.2026 16:57:03
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 thr...
CVE-2026-59083
- EPSS 0.37%
- Veröffentlicht 14.07.2026 08:13:04
- Zuletzt bearbeitet 14.07.2026 16:57:31
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1...
CVE-2026-55957
- EPSS 2.86%
- Veröffentlicht 29.06.2026 20:47:12
- Zuletzt bearbeitet 02.07.2026 19:01:45
Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: fr...
CVE-2026-55956
- EPSS 1.53%
- Veröffentlicht 29.06.2026 20:46:02
- Zuletzt bearbeitet 02.07.2026 19:03:30
Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 throu...
CVE-2026-55955
- EPSS 0.47%
- Veröffentlicht 29.06.2026 20:44:39
- Zuletzt bearbeitet 10.07.2026 12:22:23
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 ...
CVE-2026-55276
- EPSS 0.54%
- Veröffentlicht 29.06.2026 20:42:23
- Zuletzt bearbeitet 02.07.2026 19:05:18
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 throug...
CVE-2026-53434
- EPSS 0.53%
- Veröffentlicht 29.06.2026 20:41:06
- Zuletzt bearbeitet 02.07.2026 19:06:09
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118...