tomcat10-jsvc

Direct Vulnerabilities

Known vulnerabilities in the tomcat10-jsvc package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Incorrect Authorization

<10.1.59-160000.1.1
  • M
Improper Authorization

<10.1.59-160000.1.1
  • H
Resource Exhaustion

<10.1.59-160000.1.1
  • M
Insufficient Session Expiration

<10.1.59-160000.1.1
  • M
Time-of-check Time-of-use (TOCTOU)

<10.1.59-160000.1.1
  • M
Authentication Bypass

<10.1.59-160000.1.1
  • M
Improper Authentication

<10.1.59-160000.1.1
  • H
Resource Exhaustion

<10.1.59-160000.1.1
  • H
Off-by-one Error

<10.1.59-160000.1.1
  • H
Improper Input Validation

<10.1.59-160000.1.1
  • H
Improper Input Validation

<10.1.59-160000.1.1
  • H
Improper Access Control

<10.1.59-160000.1.1
  • H
Resource Exhaustion

<10.1.59-160000.1.1
  • H
Resource Exhaustion

<10.1.59-160000.1.1
  • M
Time-of-check Time-of-use (TOCTOU)

<10.1.59-160000.1.1
  • M
Incorrect Authorization

<10.1.59-160000.1.1
  • H
Improper Input Validation

<10.1.59-160000.1.1
  • M
Improper Authorization

<10.1.59-160000.1.1
  • H
Improper Input Validation

<10.1.59-160000.1.1
  • M
Insufficient Session Expiration

<10.1.59-160000.1.1
  • H
Off-by-one Error

<10.1.59-160000.1.1
  • M
Improper Authentication

<10.1.59-160000.1.1
  • M
Authentication Bypass

<10.1.59-160000.1.1
  • H
Improper Access Control

<10.1.59-160000.1.1
  • M
Improper Authorization

<10.1.56-160000.1.1
  • M
Improper Authentication

<10.1.56-160000.1.1
  • L
Always-Incorrect Control Flow Implementation

<10.1.56-160000.1.1
  • M
Detection of Error Condition Without Action

<10.1.56-160000.1.1
  • M
Cross-site Scripting (XSS)

<10.1.56-160000.1.1
  • M
Always-Incorrect Control Flow Implementation

<10.1.56-160000.1.1
  • M
Allocation of Resources Without Limits or Throttling

<10.1.55-160000.1.1
  • M
Improper Handling of Case Sensitivity

<10.1.55-160000.1.1
  • M
Information Exposure

<10.1.55-160000.1.1
  • M
Information Exposure

<10.1.55-160000.1.1
  • H
Improper Authorization

<10.1.55-160000.1.1
  • H
Authentication Bypass

<10.1.55-160000.1.1
  • H
Improper Input Validation

<10.1.55-160000.1.1
  • M
CVE-2026-34500

<10.1.54-160000.1.1
  • M
Information Exposure Through Log Files

<10.1.54-160000.1.1
  • H
Improper Input Validation

<10.1.54-160000.1.1
  • H
Missing Encryption of Sensitive Data

<10.1.54-160000.1.1
  • H
CVE-2026-29146

<10.1.54-160000.1.1
  • M
CVE-2026-29145

<10.1.54-160000.1.1
  • M
Improper Encoding or Escaping of Output

<10.1.54-160000.1.1
  • M
HTTP Request Smuggling

<10.1.54-160000.1.1
  • M
CVE-2026-29129

<10.1.54-160000.1.1
  • M
Open Redirect

<10.1.54-160000.1.1
  • H
Improper Certificate Validation

<10.1.54-160000.1.1
  • M
CVE-2026-24734

<10.1.52-160000.1.1
  • M
Improper Resource Shutdown or Release

<10.1.52-160000.1.1
  • M
CVE-2026-24733

<10.1.52-160000.1.1
  • H
Improper Certificate Validation

<10.1.52-160000.1.1
  • M
Improper Neutralization

<10.1.52-160000.1.1
  • H
Directory Traversal

<10.1.52-160000.1.1