Search CVE reports


Toggle filters

1 – 10 of 171 results


CVE-2026-87022

Medium priority
Needs evaluation

Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25,...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release — —
tomcat7 Not in release Not in release Not in release — Not affected
tomcat8 Not in release Not in release Not in release — Needs evaluation
tomcat9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tomcat10 Needs evaluation Needs evaluation Not in release — —
tomcat11 Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-86350

Medium priority
Needs evaluation

Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release — —
tomcat7 Not in release Not in release Not in release — Not affected
tomcat8 Not in release Not in release Not in release — Needs evaluation
tomcat9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tomcat10 Needs evaluation Needs evaluation Not in release — —
tomcat11 Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-86248

Medium priority
Needs evaluation

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59,...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release — —
tomcat7 Not in release Not in release Not in release — Not affected
tomcat8 Not in release Not in release Not in release — Needs evaluation
tomcat9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tomcat10 Needs evaluation Needs evaluation Not in release — —
tomcat11 Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-79677

Medium priority
Needs evaluation

Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost time outs for asynchronous WebSocket writes. This issue affects...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release — —
tomcat7 Not in release Not in release Not in release — Not affected
tomcat8 Not in release Not in release Not in release — Needs evaluation
tomcat9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tomcat10 Needs evaluation Needs evaluation Not in release — —
tomcat11 Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-78437

Medium priority
Needs evaluation

Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. This issue affects Apache Tomcat: from 11.0.19 through 11.0.25,...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release — —
tomcat7 Not in release Not in release Not in release — Not affected
tomcat8 Not in release Not in release Not in release — Needs evaluation
tomcat9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tomcat10 Needs evaluation Needs evaluation Not in release — —
tomcat11 Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-78383

Medium priority
Needs evaluation

Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial of service. This issue affects Apache Tomcat: from...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release — —
tomcat7 Not in release Not in release Not in release — Not affected
tomcat8 Not in release Not in release Not in release — Needs evaluation
tomcat9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tomcat10 Needs evaluation Needs evaluation Not in release — —
tomcat11 Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-77791

Medium priority
Needs evaluation

Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomcat: from 11.0.0-M5 through 11.0.25, from 10.1.8 through 10.1.59, from...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release — —
tomcat7 Not in release Not in release Not in release — Not affected
tomcat8 Not in release Not in release Not in release — Needs evaluation
tomcat9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tomcat10 Needs evaluation Needs evaluation Not in release — —
tomcat11 Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-77762

Medium priority
Needs evaluation

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an attacker to inject trailer fields into another HTTP/2 request. This issue affects Apache Tomcat:...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release — —
tomcat7 Not in release Not in release Not in release — Not affected
tomcat8 Not in release Not in release Not in release — Needs evaluation
tomcat9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tomcat10 Needs evaluation Needs evaluation Not in release — —
tomcat11 Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-77756

Medium priority
Needs evaluation

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused by processing the transfer-encoding header for an HTTP/1.0 request may allow an attacker to cause one request...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release — —
tomcat7 Not in release Not in release Not in release — Not affected
tomcat8 Not in release Not in release Not in release — Needs evaluation
tomcat9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tomcat10 Needs evaluation Needs evaluation Not in release — —
tomcat11 Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-76183

Medium priority
Needs evaluation

Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release — —
tomcat7 Not in release Not in release Not in release — Not affected
tomcat8 Not in release Not in release Not in release — Needs evaluation
tomcat9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tomcat10 Needs evaluation Needs evaluation Not in release — —
tomcat11 Needs evaluation Not in release Not in release — —
Show less packages