Known Vulnerabilities for Apache Tomcat by Apache Software Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Apache Tomcat" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66713 json | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-66299 json | Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat:... | Not Provided | 2026-07-28 | 2026-07-28 |
| CVE-2026-59084 json | Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptI... | Not Provided | 2026-07-14 | 2026-07-14 |
| CVE-2026-59083 json | Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint b... | Not Provided | 2026-07-14 | 2026-07-14 |
| CVE-2026-55957 json | Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate bind... | Not Provided | 2026-06-29 | 2026-06-30 |
| CVE-2026-55956 json | Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignorin... | Not Provided | 2026-06-29 | 2026-06-30 |
| CVE-2026-55955 json | Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the clust... | Not Provided | 2026-06-29 | 2026-06-30 |
| CVE-2026-55276 json | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation ... | Not Provided | 2026-06-29 | 2026-06-30 |
| CVE-2026-53434 json | Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. ... | Not Provided | 2026-06-29 | 2026-06-30 |
| CVE-2026-53404 json | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition... | Not Provided | 2026-06-29 | 2026-06-30 |