Apache tomcat
This hub aggregates every CVE we track for Apache tomcat, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
289
CVEs tracked
27
Critical
102
High
7
In CISA KEV
Severity distribution
MEDIUM144HIGH102CRITICAL27LOW16
Monthly trend
0
4
3
0
0
1
2
1
3
3
2
0
3
0
0
0
3
0
10
7
7
3
10
12
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache tomcat.
- CVE-2026-87022Apache Tomcat: WebSocket message smuggling with per-message-deflate7.5
- CVE-2026-86350Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up9.1
- CVE-2026-86248Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled9.8
- CVE-2026-79677Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout7.5
- CVE-2026-78437Apache Tomcat: HTTP/2 DoS via malformed request7.3
- CVE-2026-78383Apache Tomcat: AJP DoS via missing request body7.5
- CVE-2026-77791Apache Tomcat: DoS via busy wait during WebSocket close7.5
- CVE-2026-77762Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request8.1
- CVE-2026-77756Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests3.7
- CVE-2026-76183Apache Tomcat: Bypass of security constraints for WebSocket endpoints9.8
- CVE-2026-75973Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured7.3
- CVE-2026-73581Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore6.5
- CVE-2026-73180Apache Tomcat: Authenticated WebSocket session survives end of HTTP session6.8
- CVE-2026-68763Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset7.5
- CVE-2026-68569Apache Tomcat: Principal lookup can fail open in some cases8.1
Product normalization is registry-driven with AI assist and human review. How it works