Org.apache.tomcat:tomcat
145 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Org.apache.tomcat:tomcat, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Org.apache.tomcat:tomcat CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 1 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 3 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 145 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High33
- Medium100
- Low10
Latest CVEs
The 15 most recently published vulnerabilities affecting Org.apache.tomcat:tomcat.
- CVE-2025-66614Apache Tomcat: Client certificate verification bypass due to virtual host mapping7.6
- CVE-2025-61795Apache Tomcat: Delayed cleaning of multi-part upload temporary files may lead to DoS5.3
- CVE-2025-55752Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled7.5
- CVE-2025-55754Apache Tomcat: console manipulation via escape sequences in log messages9.6
- CVE-2025-49124Apache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for Windows8.4
- CVE-2024-54677Apache Tomcat: DoS in examples web application5.3
- CVE-2024-52318Apache Tomcat: Incorrect JSP tag recycling leads to XSS6.1
- CVE-2023-45648Apache Tomcat: Trailer header parsing too lenient5.3
- CVE-2023-42795Apache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requests5.3
- CVE-2023-41080Apache Tomcat: Open redirect with FORM authentication6.1
- CVE-2021-43980Apache Tomcat: Information disclosure3.7
- CVE-2022-34305XSS in examples web application6.1
- CVE-2022-25762Response mix-up with WebSocket concurrent send and close8.6
- CVE-2022-29885EncryptInterceptor does not provide complete protection on insecure networks7.5
- CVE-2022-23181Local privilege escalation with FileStore7.0
Product grouping is registry-driven, with AI assist and human review. How it works