Apache Tomcat
289 CVEs tracked. 7 of them are in CISA KEV.
This hub aggregates every CVE we track for Apache Tomcat, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
Apache Tomcat CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 4 |
| 2024-12 | 3 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 2 |
| 2025-05 | 1 |
| 2025-06 | 3 |
| 2025-07 | 3 |
| 2025-08 | 2 |
| 2025-09 | 0 |
| 2025-10 | 3 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 3 |
| 2026-03 | 0 |
| 2026-04 | 10 |
| 2026-05 | 7 |
| 2026-06 | 7 |
| 2026-07 | 3 |
| 2026-08 | 10 |
| 2026-09 | 12 |
Severity
How the 289 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical27
- High102
- Medium144
- Low16
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache Tomcat.
- CVE-2026-87022Apache Tomcat: WebSocket message smuggling with per-message-deflate7.5
- CVE-2026-86350Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up9.1
- CVE-2026-86248Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled9.8
- CVE-2026-79677Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout7.5
- CVE-2026-78437Apache Tomcat: HTTP/2 DoS via malformed request7.3
- CVE-2026-78383Apache Tomcat: AJP DoS via missing request body7.5
- CVE-2026-77791Apache Tomcat: DoS via busy wait during WebSocket close7.5
- CVE-2026-77762Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request8.1
- CVE-2026-77756Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests3.7
- CVE-2026-76183Apache Tomcat: Bypass of security constraints for WebSocket endpoints9.8
- CVE-2026-75973Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured7.3
- CVE-2026-73581Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore6.5
- CVE-2026-73180Apache Tomcat: Authenticated WebSocket session survives end of HTTP session6.8
- CVE-2026-68763Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset7.5
- CVE-2026-68569Apache Tomcat: Principal lookup can fail open in some cases8.1
Product grouping is registry-driven, with AI assist and human review. How it works