Known Vulnerabilities for Tomcat by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Tomcat" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-43515 json | Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache ... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-43514 json | Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: f... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-43513 json | Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-43512 json | DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache ... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-42498 json | Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. T... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-41293 json | Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, ... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-41284 json | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from ... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-40075 json | OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 th... | Not Provided | 2026-05-05 | 2026-05-06 |
| CVE-2026-34500 json | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache ... | Not Provided | 2026-04-09 | 2026-04-10 |
| CVE-2026-34487 json | Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tom... | Not Provided | 2026-04-09 | 2026-04-10 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Tomcat | 9.0.9 | |||
| Application | Apache | Tomcat | 9.0.8 | |||
| Application | Apache | Tomcat | 9.0.7 | |||
| Application | Apache | Tomcat | 9.0.6 | |||
| Application | Apache | Tomcat | 9.0.5 | |||
| Application | Apache | Tomcat | 9.0.43 | |||
| Application | Apache | Tomcat | 9.0.41 | |||
| Application | Apache | Tomcat | 9.0.40 | |||
| Application | Apache | Tomcat | 9.0.4 | |||
| Application | Apache | Tomcat | 9.0.39 | |||
| Application | Apache | Tomcat | 9.0.38 | |||
| Application | Apache | Tomcat | 9.0.37 | |||
| Application | Apache | Tomcat | 9.0.36 | |||
| Application | Apache | Tomcat | 9.0.35-3.57.3 | |||
| Application | Apache | Tomcat | 9.0.35-3.39.1 | |||
| Application | Apache | Tomcat | 9.0.35 | |||
| Application | Apache | Tomcat | 9.0.34 | |||
| Application | Apache | Tomcat | 9.0.33 | |||
| Application | Apache | Tomcat | 9.0.32 | |||
| Application | Apache | Tomcat | 9.0.31 |