| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-73180 | vulnerable | vulnerable | vulnerable | vulnerable | Insufficient Session Expiration vulnerability in Apache Tomcat meant t ... |
| CVE-2026-68763 | vulnerable | vulnerable | vulnerable | vulnerable | Uncontrolled Resource Consumption vulnerability in Apache Tomcatvia an ... |
| CVE-2026-68569 | vulnerable | vulnerable | vulnerable | vulnerable | Improper Authentication vulnerability in Apache Tomcat meant that in s ... |
| CVE-2026-68525 | vulnerable | vulnerable | vulnerable | vulnerable | Incorrect Authorization vulnerability in Apache Tomcat's FORM authenti ... |
| CVE-2026-66422 | vulnerable | vulnerable | vulnerable | vulnerable | Improper Authorization vulnerability in Apache Tomcat cause by securit ... |
| CVE-2026-65927 | vulnerable | vulnerable | vulnerable | vulnerable | Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag ... |
| CVE-2026-65905 | vulnerable | vulnerable | vulnerable | vulnerable | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat ... |
| CVE-2026-65637 | vulnerable | vulnerable | vulnerable | vulnerable | Improper Input Validation vulnerability in Apache Tomcat due to incomp ... |
| CVE-2026-65183 | vulnerable | vulnerable | vulnerable | vulnerable | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apa ... |
| CVE-2026-65182 | vulnerable | vulnerable | vulnerable | vulnerable | Improper Access Control, Incorrect Authorization vulnerability in Apac ... |
| CVE-2026-59084 | vulnerable | vulnerable | vulnerable | vulnerable | Insufficient Technical Documentation vulnerability in Apache Tomcat si ... |
| CVE-2026-59083 | vulnerable | vulnerable | vulnerable | vulnerable | Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apac ... |
| CVE-2026-55956 | vulnerable | vulnerable | vulnerable | vulnerable | Improper Authorization vulnerability in Apache Tomcat leads to securit ... |
| CVE-2026-55955 | vulnerable | vulnerable | vulnerable | vulnerable | Improper Authentication vulnerability in Apache Tomcat allowed a repla ... |
| CVE-2026-55276 | vulnerable | vulnerable | vulnerable | vulnerable | Always-Incorrect Control Flow Implementation vulnerability in Apache T ... |
| CVE-2026-53434 | vulnerable | vulnerable | vulnerable | vulnerable | Detection of Error Condition Without Action vulnerability in Apache To ... |
| CVE-2026-53404 | vulnerable | vulnerable | vulnerable | vulnerable | Always-Incorrect Control Flow Implementation vulnerability in Apache T ... |
| CVE-2026-50229 | vulnerable | vulnerable | vulnerable | vulnerable | Improper Neutralization of Script-Related HTML Tags in a Web Page (Bas ... |
| Bug | Description |
|---|
| CVE-2026-55957 | Missing Critical Step in Authentication vulnerability in Apache Tomcat ... |
| CVE-2026-43515 | Improper Authorization vulnerability when multiple method constraints ... |
| CVE-2026-43514 | Observable Timing Discrepancy vulnerabilitywhen comparing AJP secret i ... |
| CVE-2026-43513 | Improper Handling of Case Sensitivity vulnerability in LockOutRealm in ... |
| CVE-2026-43512 | DEPRECATED: Authentication Bypass Issues vulnerability in digest authe ... |
| CVE-2026-42498 | Exposure of HTTP Authentication Header to unexpected hosts during WebS ... |
| CVE-2026-41293 | Improper Input Validation vulnerability in Apache Tomcat. This issue ... |
| CVE-2026-41284 | Allocation of Resources Without Limits or Throttling vulnerability in ... |
| CVE-2026-34500 | CLIENT_CERT authentication does not fail as expected for some scenario ... |
| CVE-2026-34487 | Insertion of Sensitive Information into Log File vulnerability in the ... |
| CVE-2026-34486 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat du ... |
| CVE-2026-34483 | Improper Encoding or Escaping of Output vulnerability in the JsonAcces ... |
| CVE-2026-32990 | Improper Input Validation vulnerability in Apache Tomcat due to an inc ... |
| CVE-2026-29146 | Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor wit ... |
| CVE-2026-29145 | CLIENT_CERT authentication does not fail as expected for some scenario ... |
| CVE-2026-29129 | Configured cipher preference order not preserved vulnerability in Apac ... |
| CVE-2026-25854 | Occasional URL redirection to untrusted Site ('Open Redirect') vulnera ... |
| CVE-2026-24880 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ... |
| CVE-2026-24734 | Improper Input Validation vulnerability in Apache Tomcat Native, Apach ... |
| CVE-2026-24733 | Improper Input Validation vulnerability in Apache Tomcat. Tomcat did ... |
| CVE-2025-66614 | Improper Input Validation vulnerability. This issue affects Apache To ... |
| CVE-2025-61795 | Improper Resource Shutdown or Release vulnerability in Apache Tomcat. ... |
| CVE-2025-55754 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ... |
| CVE-2025-55752 | Relative Path Traversal vulnerability in Apache Tomcat. The fix for b ... |
| CVE-2025-55668 | Session Fixation vulnerability in Apache Tomcat via rewrite valve. Th ... |
| CVE-2025-53506 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an ... |
| CVE-2025-52520 | For some unlikely configurations of multipart upload, an Integer Overf ... |
| CVE-2025-49125 | Authentication Bypass Using an Alternate Path or Channel vulnerability ... |
| CVE-2025-49124 | Untrusted Search Path vulnerability in Apache Tomcat installer for Win ... |
| CVE-2025-48989 | Improper Resource Shutdown or Release vulnerability in Apache Tomcat m ... |
| CVE-2025-48988 | Allocation of Resources Without Limits or Throttling vulnerability in ... |
| CVE-2025-48976 | Allocation of resources for multipart headers with insufficient limits ... |
| CVE-2025-46701 | Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's ... |
| CVE-2025-31651 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ... |
| CVE-2025-31650 | Improper Input Validation vulnerability in Apache Tomcat. Incorrect er ... |
| CVE-2025-24813 | Path Equivalence: 'file.Name' (Internal Dot) leading toRemote Code Exe ... |
| CVE-2024-56337 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apa ... |
| CVE-2024-54677 | Uncontrolled Resource Consumption vulnerability in the examples web ap ... |
| CVE-2024-52318 | Incorrect object recycling and reuse vulnerability in Apache Tomcat. ... |
| CVE-2024-52317 | Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. ... |
| CVE-2024-52316 | Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is ... |
| CVE-2024-50379 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during ... |
| CVE-2024-38286 | Allocation of Resources Without Limits or Throttling vulnerability in ... |
| CVE-2024-34750 | Improper Handling of Exceptional Conditions, Uncontrolled Resource Con ... |
| CVE-2024-24549 | Denial of Service due to improper input validation vulnerability for H ... |
| CVE-2024-23672 | Denial of Service via incomplete cleanup vulnerability in Apache Tomca ... |
| CVE-2024-22029 | Insecure permissions in the packaging of tomcat allow local users that ... |
| CVE-2023-46589 | Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 1 ... |
| CVE-2023-45648 | Improper Input Validation vulnerability in Apache Tomcat.Tomcatfrom 11 ... |
| CVE-2023-44487 | The HTTP/2 protocol allows a denial of service (server resource consum ... |
| CVE-2023-42795 | Incomplete Cleanup vulnerability in Apache Tomcat.When recycling vario ... |
| CVE-2023-42794 | Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork ... |
| CVE-2023-41080 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in F ... |
| CVE-2023-34981 | A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1 ... |
| CVE-2023-28709 | The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 ... |
| CVE-2023-28708 | When using the RemoteIpFilter with requests received from a reverse ... |
| CVE-2023-24998 | Apache Commons FileUpload before 1.5 does not limit the number of requ ... |