Known Vulnerabilities for Apache Tomcat by Apache Software Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Apache Tomcat" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73180 json | Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-68763 json | Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when ... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-68569 json | Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a use... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-68525 json | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security const... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-66713 json | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-66422 json | Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role a... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-66299 json | Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat:... | Not Provided | 2026-07-28 | 2026-07-28 |
| CVE-2026-65927 json | Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to res... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-65905 json | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-65637 json | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apac... | Not Provided | 2026-08-25 | 2026-08-26 |