Direct Vulnerabilities

Known vulnerabilities in the tomcat package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Symbolic Name not Mapping to Correct Object

*
  • M
HTTP Request Smuggling

*
  • M
Insufficient Session Expiration

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • H
Off-by-one Error

*
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • M
Authentication Bypass

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Authentication Bypass by Primary Weakness

*
  • H
Incomplete Cleanup

<1:10.1.36-1.el10_0
  • H
Resource Exhaustion

<1:10.1.36-1.el10_0
  • M
Open Redirect

<1:10.1.36-1.el10_0
  • M
Improper Input Validation

<1:10.1.36-1.el10_0
  • M
Time-of-check Time-of-use (TOCTOU)

<1:10.1.36-1.el10_0
  • M
Incomplete Cleanup

<1:10.1.36-1.el10_0
  • H
Improper Input Validation

<1:10.1.36-1.el10_0
  • H
HTTP Request Smuggling

<1:10.1.36-1.el10_0
  • H
Improper Input Validation

<1:10.1.49-1.el10
  • H
Authentication Bypass by Primary Weakness

<1:10.1.49-1.el10
  • M
Incorrect Implementation of Authentication Algorithm

<1:10.1.49-4.el10_2
  • M
Information Exposure

<1:10.1.49-4.el10_2
  • M
Improper Validation of Syntactic Correctness of Input

<1:10.1.49-4.el10_2
  • M
Incomplete Blacklist

<1:10.1.49-4.el10_2
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:10.1.49-4.el10_2
  • M
Improper Handling of Case Sensitivity

<1:10.1.49-4.el10_2
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:10.1.49-1.el10_0
  • H
Authentication Bypass by Primary Weakness

<1:10.1.49-1.el10_0
  • M
Incomplete Blacklist

<1:10.1.49-1.el10_0
  • M
Improper Handling of Case Sensitivity

<1:10.1.49-1.el10_0
  • M
Improper Validation of Syntactic Correctness of Input

<1:10.1.49-1.el10_0
  • M
Information Exposure

<1:10.1.49-1.el10_0
  • M
Incorrect Implementation of Authentication Algorithm

<1:10.1.49-1.el10_0
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Authentication Bypass by Primary Weakness

*
  • H
Authentication Bypass by Primary Weakness

*
  • H
Authentication Bypass by Primary Weakness

*
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • M
Authentication Bypass

*
  • M
Authentication Bypass

*
  • M
Authentication Bypass

*
  • M
Insufficient Session Expiration

*
  • M
Insufficient Session Expiration

*
  • M
Insufficient Session Expiration

*
  • L
Symbolic Name not Mapping to Correct Object

*
  • L
Symbolic Name not Mapping to Correct Object

*
  • L
Symbolic Name not Mapping to Correct Object

*
  • H
Off-by-one Error

*
  • H
Off-by-one Error

*
  • H
Off-by-one Error

*
  • M
HTTP Request Smuggling

*
  • M
HTTP Request Smuggling

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Uncaught Exception

*
  • L
Insecure Default Initialization of Resource

*
  • L
Reliance on Untrusted Inputs in a Security Decision

*
  • H
Use of a Risky Cryptographic Primitive

<1:10.1.49-3.el10_2
  • H
Use of a Risky Cryptographic Primitive

<1:10.1.36-2.el10_0
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:10.1.49-3.el10_2
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:10.1.36-2.el10_0
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • L
Insufficient Logging

*
  • L
Detection of Error Condition Without Action

*
  • M
Authentication Bypass

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improperly Implemented Security Check for Standard

*
  • M
Improper Neutralization

<1:10.1.49-1.el10
  • H
Improper Certificate Validation

<1:10.1.49-1.el10_2.1
  • M
Session Fixation

<1:10.1.49-1.el10
  • M
Improper Handling of Case Sensitivity

<1:10.1.49-1.el10
  • L
Inappropriate Encoding for Output Context

*
  • L
HTTP Request Smuggling

*
  • L
HTTP Request Smuggling

*
  • L
File and Directory Information Exposure

*
  • M
Incomplete Blacklist

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • L
Open Redirect

*
  • L
Open Redirect

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Access Control

*
  • M
Improper Access Control

*
  • H
Improper Certificate Validation

*
  • L
Improper Input Validation

*
  • L
Improper Input Validation

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • L
Improper Input Validation

*
  • L
Improper Neutralization

<1:10.1.36-3.el10_1.1
  • L
Improper Neutralization

<1:10.1.36-1.el10_0.3
  • M
Improper Resource Shutdown or Release

<1:10.1.36-3.el10_1.1
  • M
Improper Resource Shutdown or Release

<1:10.1.36-1.el10_0.3
  • H
Directory Traversal

<1:10.1.36-3.el10_1.1
  • H
Directory Traversal

<1:10.1.36-1.el10_0.3
  • M
Allocation of Resources Without Limits or Throttling

<1:10.1.36-1.el10_0.2
  • H
Resource Exhaustion

<1:10.1.36-1.el10_0.2
  • L
Authentication Bypass

<1:10.1.36-1.el10_0.2
  • M
Allocation of Resources Without Limits or Throttling

<1:10.1.36-1.el10_0.2
  • M
Resource Exhaustion

<1:10.1.36-1.el10_0.2
  • L
Integer Overflow or Wraparound

<1:10.1.36-1.el10_0.2
  • M
Improper Handling of Case Sensitivity

*
  • L
Resource Exhaustion

<1:10.1.36-1.el10_0
  • L
Uncaught Exception

<1:10.1.36-1.el10_0
  • M
Path Equivalence

<1:10.1.36-1.el10_0
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Off-by-one Error

*
  • M
Access Restriction Bypass

*
  • L
Cross-site Scripting (XSS)

*
  • L
Cross-site Scripting (XSS)

*
  • L
HTTP Request Smuggling

*