Apache Tomcat

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-55957

    Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind

    Last Modified: Jul 01, 2026
    Published: Jun 29, 2026

    CVE-2026-24734

    Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass

    Last Modified: Apr 16, 2026
    Published: Feb 17, 2026

    CVE-2026-24733

    Apache Tomcat: Security constraint bypass with HTTP/0.9

    Last Modified: Apr 16, 2026
    Published: Feb 17, 2026

    CVE-2025-66614

    Apache Tomcat: Client certificate verification bypass due to virtual host mapping

    Last Modified: Mar 24, 2026
    Published: Feb 17, 2026

    CVE-2005-1754

    JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products.

    Last Modified: Apr 16, 2026
    Published: Dec 31, 2005
    Items Per Page
    Apache_Tomcat Vulnerabilities & Security CVEs | CVE-DB