tomcat10-servlet-6_0-api

Direct Vulnerabilities

Known vulnerabilities in the tomcat10-servlet-6_0-api package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Improper Authorization

<10.1.59-160000.1.1
  • H
Resource Exhaustion

<10.1.59-160000.1.1
  • M
Time-of-check Time-of-use (TOCTOU)

<10.1.59-160000.1.1
  • M
Improper Authentication

<10.1.59-160000.1.1
  • M
Insufficient Session Expiration

<10.1.59-160000.1.1
  • H
Resource Exhaustion

<10.1.59-160000.1.1
  • M
Incorrect Authorization

<10.1.59-160000.1.1
  • H
Improper Access Control

<10.1.59-160000.1.1
  • M
Authentication Bypass

<10.1.59-160000.1.1
  • H
Improper Input Validation

<10.1.59-160000.1.1
  • H
Improper Input Validation

<10.1.59-160000.1.1
  • H
Off-by-one Error

<10.1.59-160000.1.1
  • H
Off-by-one Error

<10.1.59-160000.1.1
  • M
Time-of-check Time-of-use (TOCTOU)

<10.1.59-160000.1.1
  • H
Improper Input Validation

<10.1.59-160000.1.1
  • M
Improper Authorization

<10.1.59-160000.1.1
  • M
Improper Authentication

<10.1.59-160000.1.1
  • H
Improper Access Control

<10.1.59-160000.1.1
  • H
Resource Exhaustion

<10.1.59-160000.1.1
  • M
Insufficient Session Expiration

<10.1.59-160000.1.1
  • H
Resource Exhaustion

<10.1.59-160000.1.1
  • M
Authentication Bypass

<10.1.59-160000.1.1
  • M
Incorrect Authorization

<10.1.59-160000.1.1
  • H
Improper Input Validation

<10.1.59-160000.1.1
  • M
Improper Authorization

<10.1.56-160000.1.1
  • M
Always-Incorrect Control Flow Implementation

<10.1.56-160000.1.1
  • L
Always-Incorrect Control Flow Implementation

<10.1.56-160000.1.1
  • M
Detection of Error Condition Without Action

<10.1.56-160000.1.1
  • M
Improper Authentication

<10.1.56-160000.1.1
  • M
Cross-site Scripting (XSS)

<10.1.56-160000.1.1
  • H
Improper Authorization

<10.1.55-160000.1.1
  • H
Authentication Bypass

<10.1.55-160000.1.1
  • M
Information Exposure

<10.1.55-160000.1.1
  • H
Improper Input Validation

<10.1.55-160000.1.1
  • M
Improper Handling of Case Sensitivity

<10.1.55-160000.1.1
  • M
Information Exposure

<10.1.55-160000.1.1
  • M
Allocation of Resources Without Limits or Throttling

<10.1.55-160000.1.1
  • M
CVE-2026-34500

<10.1.54-160000.1.1
  • H
Improper Input Validation

<10.1.54-160000.1.1
  • M
Information Exposure Through Log Files

<10.1.54-160000.1.1
  • M
CVE-2026-29145

<10.1.54-160000.1.1
  • M
HTTP Request Smuggling

<10.1.54-160000.1.1
  • M
Improper Encoding or Escaping of Output

<10.1.54-160000.1.1
  • M
Open Redirect

<10.1.54-160000.1.1
  • H
CVE-2026-29146

<10.1.54-160000.1.1
  • H
Improper Certificate Validation

<10.1.54-160000.1.1
  • H
Missing Encryption of Sensitive Data

<10.1.54-160000.1.1
  • M
CVE-2026-29129

<10.1.54-160000.1.1
  • M
CVE-2026-24734

<10.1.52-160000.1.1
  • M
CVE-2026-24733

<10.1.52-160000.1.1
  • H
Improper Certificate Validation

<10.1.52-160000.1.1
  • M
Improper Resource Shutdown or Release

<10.1.52-160000.1.1
  • H
Directory Traversal

<10.1.52-160000.1.1
  • M
Improper Neutralization

<10.1.52-160000.1.1