Apache

Tomcat

288 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht
  • EPSS 82.93%
  • Veröffentlicht 09.04.2026 20:16:25
  • Zuletzt bearbeitet 21.09.2026 19:17:04

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to ve...

  • EPSS 0.45%
  • Veröffentlicht 09.04.2026 20:16:25
  • Zuletzt bearbeitet 14.04.2026 12:44:45

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 th...

  • EPSS 0.47%
  • Veröffentlicht 09.04.2026 20:16:25
  • Zuletzt bearbeitet 14.04.2026 12:43:28

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through...

  • EPSS 0.52%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 20:02:48

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0...

  • EPSS 0.53%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 14:01:07

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through...

  • EPSS 0.26%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 14:00:19

Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version...

Medienbericht
  • EPSS 0.72%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 13:22:28

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52...

Medienbericht
  • EPSS 6.26%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 04.08.2026 13:18:02

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100,...

  • EPSS 0.31%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 12:47:51

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended t...

  • EPSS 0.46%
  • Veröffentlicht 09.04.2026 20:16:24
  • Zuletzt bearbeitet 14.04.2026 12:46:39

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are rec...