tomcat11-servlet-6_1-api

Direct Vulnerabilities

Known vulnerabilities in the tomcat11-servlet-6_1-api package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Resource Exhaustion

<11.0.25-160000.1.1
  • H
Resource Exhaustion

<11.0.25-160000.1.1
  • M
Improper Authorization

<11.0.25-160000.1.1
  • M
Insufficient Session Expiration

<11.0.25-160000.1.1
  • H
Improper Access Control

<11.0.25-160000.1.1
  • M
Incorrect Authorization

<11.0.25-160000.1.1
  • M
Insufficient Session Expiration

<11.0.25-160000.1.1
  • H
Improper Input Validation

<11.0.25-160000.1.1
  • M
Improper Authentication

<11.0.25-160000.1.1
  • M
Incorrect Authorization

<11.0.25-160000.1.1
  • H
Improper Input Validation

<11.0.25-160000.1.1
  • H
Off-by-one Error

<11.0.25-160000.1.1
  • M
Authentication Bypass

<11.0.25-160000.1.1
  • M
Time-of-check Time-of-use (TOCTOU)

<11.0.25-160000.1.1
  • H
Improper Input Validation

<11.0.25-160000.1.1
  • M
Improper Authorization

<11.0.25-160000.1.1
  • M
Time-of-check Time-of-use (TOCTOU)

<11.0.25-160000.1.1
  • H
Resource Exhaustion

<11.0.25-160000.1.1
  • M
Improper Authentication

<11.0.25-160000.1.1
  • M
Authentication Bypass

<11.0.25-160000.1.1
  • H
Off-by-one Error

<11.0.25-160000.1.1
  • H
Resource Exhaustion

<11.0.25-160000.1.1
  • H
Improper Access Control

<11.0.25-160000.1.1
  • H
Improper Input Validation

<11.0.25-160000.1.1
  • M
Improper Authorization

<11.0.23-160000.1.1
  • L
Always-Incorrect Control Flow Implementation

<11.0.23-160000.1.1
  • M
Improper Authentication

<11.0.23-160000.1.1
  • M
Detection of Error Condition Without Action

<11.0.23-160000.1.1
  • M
Cross-site Scripting (XSS)

<11.0.23-160000.1.1
  • M
Always-Incorrect Control Flow Implementation

<11.0.23-160000.1.1
  • M
Information Exposure

<11.0.22-160000.1.1
  • M
Improper Handling of Case Sensitivity

<11.0.22-160000.1.1
  • H
Improper Input Validation

<11.0.22-160000.1.1
  • M
Allocation of Resources Without Limits or Throttling

<11.0.22-160000.1.1
  • H
Improper Authorization

<11.0.22-160000.1.1
  • M
Information Exposure

<11.0.22-160000.1.1
  • H
Authentication Bypass

<11.0.22-160000.1.1
  • M
CVE-2026-29145

<11.0.21-160000.1.1
  • M
Information Exposure Through Log Files

<11.0.21-160000.1.1
  • M
CVE-2026-29129

<11.0.21-160000.1.1
  • M
Improper Encoding or Escaping of Output

<11.0.21-160000.1.1
  • M
CVE-2026-34500

<11.0.21-160000.1.1
  • H
Missing Encryption of Sensitive Data

<11.0.21-160000.1.1
  • M
HTTP Request Smuggling

<11.0.21-160000.1.1
  • H
CVE-2026-29146

<11.0.21-160000.1.1
  • M
Open Redirect

<11.0.21-160000.1.1
  • H
Improper Input Validation

<11.0.21-160000.1.1
  • H
Improper Certificate Validation

<11.0.21-160000.1.1
  • M
CVE-2026-24734

<11.0.18-160000.1.1
  • M
CVE-2026-24733

<11.0.18-160000.1.1
  • H
Improper Certificate Validation

<11.0.18-160000.1.1
  • M
Improper Neutralization

<11.0.13-160000.1.1
  • M
Improper Resource Shutdown or Release

<11.0.13-160000.1.1
  • H
Directory Traversal

<11.0.13-160000.1.1