Apache tomcat native
This hub aggregates every CVE we track for Apache tomcat native, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
8
CVEs tracked
2
Critical
5
High
0
In CISA KEV
Severity distribution
HIGH5CRITICAL2MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
1
0
0
0
0
3
2024-102026-09
Latest CVEs
The 8 most recently published vulnerabilities affecting Apache tomcat native.
- CVE-2026-86247Apache Tomcat Native: Client certificate requirements can be down-graded7.4
- CVE-2026-86246Apache Tomcat Native: Insecure OpenSSL options enabled9.1
- CVE-2026-86243Apache Tomcat Native: DoS via TLS handshake7.5
- CVE-2026-29145Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled9.1
- CVE-2026-24734Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass7.5
- CVE-2018-8019When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to be incorrectly ide...7.4
- CVE-2018-8020Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequent...7.4
- CVE-2017-15698When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result o...5.9
Product normalization is registry-driven with AI assist and human review. How it works