Apache
Apache Tomcat: vulnerabilidades y CVE
Apache Tomcat tiene 301 vulnerabilidades publicadas, 64 de ellas en los últimos 12 meses. 32 son críticas y 7 figuran en el catálogo de explotación activa de CISA.
CVE301
Últimos 12 meses64
Críticas32
Explotadas activamente7
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-34486 | Alta (7.5) | 6.6% | ⚠ Explotación activa | 9 abr 2026 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are… |
| CVE-2025-24813 | Crítica (9.8) | 100% | ⚠ Explotación activa | 10 mar 2025 | Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue… |
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2016-8735 | Crítica (9.8) | 90% | ⚠ Explotación activa | 6 abr 2017 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX… |
| CVE-2017-12615 | Alta (8.1) | 100% | ⚠ Explotación activa | 19 sept 2017 | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a… |
| CVE-2017-12617 | Alta (8.1) | 100% | ⚠ Explotación activa | 4 oct 2017 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to… |
| CVE-2020-1938 | Crítica (9.8) | 99% | ⚠ Explotación activa | 24 feb 2020 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-87022 | Alta (7.5) | 0.42% | — | 23 sept 2026 | Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25,… |
| CVE-2026-86350 | Crítica (9.1) | 0.31% | — | 23 sept 2026 | Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects… |
| CVE-2026-86248 | Crítica (9.8) | 0.39% | — | 23 sept 2026 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through… |
| CVE-2026-79677 | Alta (7.5) | 0.32% | — | 23 sept 2026 | Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost time outs for asynchronous WebSocket writes. This issue… |
| CVE-2026-78437 | Alta (7.3) | 0.26% | — | 23 sept 2026 | Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. This issue affects Apache Tomcat: from 11.0.19 through… |
| CVE-2026-78383 | Alta (7.5) | 0.38% | — | 23 sept 2026 | Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial of service. This issue affects Apache Tomcat:… |
| CVE-2026-77791 | Alta (7.5) | 0.53% | — | 23 sept 2026 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomcat: from 11.0.0-M5 through 11.0.25, from 10.1.8 through… |
| CVE-2026-77762 | Alta (8.1) | 0.36% | — | 23 sept 2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an attacker to inject trailer fields into another HTTP/2 request. This issue affects… |
| CVE-2026-77756 | Baja (3.7) | 0.26% | — | 23 sept 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused by processing the transfer-encoding header for an HTTP/1.0 request may allow an attacker to cause… |
| CVE-2026-76183 | Crítica (9.8) | 0.39% | — | 23 sept 2026 | Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from… |
| CVE-2026-75973 | Alta (7.3) | 0.24% | — | 23 sept 2026 | Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provider, the realm for the… |
| CVE-2026-73581 | Media (6.5) | 0.12% | — | 23 sept 2026 | Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apache Tomcat: from… |
| CVE-2026-73511 | Media (5.3) | 0.55% | — | 21 sept 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache… |
| CVE-2026-34151 | Alta (8.2) | 1.1% | — | 14 sept 2026 | XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application… |
| CVE-2026-82180 | Crítica (9.5) | 0.34% | — | 3 sept 2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate that the client sends inside the MQTT message… |
| CVE-2026-80515 | Alta (8.9) | 0.47% | — | 3 sept 2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling… |
| CVE-2026-49831 | Media (5.5) | 0.53% | — | 2 sept 2026 | DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the… |
| CVE-2026-73180 | Media (6.8) | 0.43% | — | 25 ago 2026 | Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP… |
| CVE-2026-68763 | Alta (7.5) | 0.86% | — | 25 ago 2026 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from… |
| CVE-2026-68569 | Alta (8.1) | 0.60% | — | 25 ago 2026 | Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue… |
| CVE-2026-68525 | Crítica (9.1) | 0.64% | — | 25 ago 2026 | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache… |
| CVE-2026-66422 | Alta (8.1) | 0.55% | — | 25 ago 2026 | Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This… |
| CVE-2026-65927 | Alta (7.5) | 0.86% | — | 25 ago 2026 | Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from… |
| CVE-2026-65905 | Crítica (9.8) | 0.78% | — | 25 ago 2026 | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper… |
| CVE-2026-65637 | Crítica (9.8) | 0.74% | — | 25 ago 2026 | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through… |
| CVE-2026-65183 | Alta (8.1) | 0.46% | — | 25 ago 2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat:… |
| CVE-2026-65182 | Crítica (9.1) | 0.65% | — | 25 ago 2026 | Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter… |
| CVE-2026-47754 | Crítica (9.3) | 0.47% | — | 10 ago 2026 | Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName`… |
| CVE-2026-66299 | Media (5.3) | 0.74% | — | 28 jul 2026 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120.… |
| CVE-2026-18047 | Media (6.5) | 0.49% | — | 28 jul 2026 | A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.