tomcat-embed

Direct Vulnerabilities

Known vulnerabilities in the tomcat-embed package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Resource Exhaustion

<9.0.121-160000.1.1
  • M
Authentication Bypass

<9.0.121-160000.1.1
  • H
Improper Input Validation

<9.0.121-160000.1.1
  • M
Time-of-check Time-of-use (TOCTOU)

<9.0.121-160000.1.1
  • H
Resource Exhaustion

<9.0.121-160000.1.1
  • H
Off-by-one Error

<9.0.121-160000.1.1
  • M
Time-of-check Time-of-use (TOCTOU)

<9.0.121-160000.1.1
  • H
Improper Input Validation

<9.0.121-160000.1.1
  • M
Insufficient Session Expiration

<9.0.121-160000.1.1
  • M
Incorrect Authorization

<9.0.121-160000.1.1
  • M
Improper Authentication

<9.0.121-160000.1.1
  • M
Improper Authorization

<9.0.121-160000.1.1
  • H
Improper Access Control

<9.0.121-160000.1.1
  • H
Improper Access Control

<9.0.121-160000.1.1
  • M
Improper Authentication

<9.0.121-160000.1.1
  • H
Resource Exhaustion

<9.0.121-160000.1.1
  • M
Authentication Bypass

<9.0.121-160000.1.1
  • H
Improper Input Validation

<9.0.121-160000.1.1
  • H
Off-by-one Error

<9.0.121-160000.1.1
  • H
Improper Input Validation

<9.0.121-160000.1.1
  • H
Resource Exhaustion

<9.0.121-160000.1.1
  • M
Incorrect Authorization

<9.0.121-160000.1.1
  • M
Improper Authorization

<9.0.121-160000.1.1
  • M
Insufficient Session Expiration

<9.0.121-160000.1.1
  • M
Improper Authentication

<9.0.119-160000.1.1
  • M
Improper Authorization

<9.0.119-160000.1.1
  • M
Detection of Error Condition Without Action

<9.0.119-160000.1.1
  • M
Always-Incorrect Control Flow Implementation

<9.0.119-160000.1.1
  • M
Cross-site Scripting (XSS)

<9.0.119-160000.1.1
  • L
Always-Incorrect Control Flow Implementation

<9.0.119-160000.1.1
  • M
Improper Handling of Case Sensitivity

<9.0.118-160000.1.1
  • M
Information Exposure

<9.0.118-160000.1.1
  • M
Allocation of Resources Without Limits or Throttling

<9.0.118-160000.1.1
  • M
Information Exposure

<9.0.118-160000.1.1
  • H
Authentication Bypass

<9.0.118-160000.1.1
  • H
Improper Authorization

<9.0.118-160000.1.1
  • H
Improper Input Validation

<9.0.118-160000.1.1
  • M
CVE-2026-29129

<9.0.117-160000.1.1
  • M
CVE-2026-34500

<9.0.117-160000.1.1
  • H
Missing Encryption of Sensitive Data

<9.0.117-160000.1.1
  • M
Information Exposure Through Log Files

<9.0.117-160000.1.1
  • M
Open Redirect

<9.0.117-160000.1.1
  • H
Improper Certificate Validation

<9.0.117-160000.1.1
  • H
CVE-2026-29146

<9.0.117-160000.1.1
  • M
HTTP Request Smuggling

<9.0.117-160000.1.1
  • H
Improper Input Validation

<9.0.117-160000.1.1
  • M
CVE-2026-29145

<9.0.117-160000.1.1
  • M
Improper Encoding or Escaping of Output

<9.0.117-160000.1.1
  • H
Directory Traversal

<9.0.111-160000.1.1
  • M
Improper Neutralization

<9.0.111-160000.1.1
  • M
Improper Resource Shutdown or Release

<9.0.111-160000.1.1