Known Vulnerabilities for Tomcat by Apache Software Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Tomcat" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82180 json | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, Ce... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-80515 json | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST en... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-73180 json | Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-68763 json | Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when ... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-68569 json | Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a use... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-68525 json | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security const... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-66713 json | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-66422 json | Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role a... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-66299 json | Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat:... | Not Provided | 2026-07-28 | 2026-07-28 |
| CVE-2026-65927 json | Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to res... | Not Provided | 2026-08-25 | 2026-08-26 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache Software Foundation | Tomcat | 4.1.8 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.7 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.6 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.5 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.4 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.33 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.30 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.27 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.26 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.25 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.23 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.22 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.21 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.20 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.19 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.18 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.17 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.16 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.14 | |||
| Application | Apache Software Foundation | Tomcat | 4.1.13 |