org.apache.tomcat:tomcat

Licenses: Apache-2.0

Direct Vulnerabilities

Known vulnerabilities in the org.apache.tomcat:tomcat package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Allocation of Resources Without Limits or Throttling

[9.0.89,9.0.121)[10.1.24,10.1.58)[11.0.0-M20,11.0.25)
  • M
Insecure Default Initialization of Resource

[9.0.13,9.0.120)[10.1.0-M1,10.1.59)[11.0.0-M1,11.0.25)
  • M
Cross-site Scripting (XSS)

[9.0.0.M1,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
  • M
Always-Incorrect Control Flow Implementation

[9.0.0.M1,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
  • M
Always-Incorrect Control Flow Implementation

[9.0.0.M1,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
  • M
Improper Authorization

[9.0.0.M1,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
  • C
Missing Critical Step in Authentication

[9.0.0-M1,9.0.101)[10.1.0-M1,10.1.37)[11.0.0-M1,11.0.5)
  • H
Detection of Error Condition Without Action

[9.0.83,9.0.119)[10.1.0-M7,10.1.56)[11.0.0-M1,11.0.23)
  • H
Improper Authentication

[9.0.13,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
  • M
Timing Attack

[,9.0.118)[10.1.0-M1,10.1.55)[11.0.0-M1,11.0.22)
  • H
Untrusted Search Path

[9.0.23,9.0.106)[10.1.0,10.1.42)[11.0.0-M1,11.0.8)
  • M
Incomplete Cleanup

[8.5.0,8.5.94)[9.0.0-M1,9.0.81)[10.1.0-M1,10.1.14)[11.0.0-M1,11.0.0-M12)
  • M
Improper Input Validation

[8.5.0,8.5.94)[9.0.0-M1,9.0.81)[10.1.0-M1,10.1.14)[11.0.0-M1,11.0.0-M12)
  • M
Incomplete Cleanup

[8.5.85,8.5.94)[9.0.70,9.0.81)
  • M
Access Restriction Bypass

[8.5.0,8.5.93)[9.0.0-M1,9.0.80)[10.1.0-M1,10.1.13)[11.0.0-M1,11.0.0-M11)
  • M
Cross-site Scripting (XSS)

[8.5.50,8.5.82)[9.0.30,9.0.65)[10.0.0-M1,10.0.23)[10.1.0-M1,10.1.0-M17)
  • H
Denial of Service (DoS)

[10.0.0,10.0.4)[8.0.0,8.5.64)[9.0.0,9.0.44)
  • M
HTTP Request Smuggling

[10.0.0-M1,10.0.7)[9.0.0.M1,9.0.48)[8.5.0,8.5.68)
  • M
Improper Input Validation

[10.0.0-M1,10.0.6)[9.0.0.M1,9.0.46)[8.5.0,8.5.66)[7.0.0,7.0.109)
  • H
Denial of Service (DoS)

[10.0.3,10.0.5)[9.0.44,9.0.45)[8.5.64,8.5.65)
  • M
Incorrectly Documented Search Algorithm

[,7.0.84)[8.0.0-RC1,8.0.48)[8.5.0,8.5.24)[9.0.0.M1,9.0.2)
  • H
Improper Access Control

[7.35,8.5.5)
  • H
Cross-site Request Forgery (CSRF)

[7,7.0.68)[8,8.0.31)[9-alpha,9.0.0.M2]
  • M
Insecure Default

[7.0.0,7.0.40)

Package versions

443 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
11.0.2512 Aug, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
11.0.243 Jul, 2026
  • 0
    C
  • 1
    H
  • 1
    M
  • 0
    L
11.0.2317 Jun, 2026
  • 0
    C
  • 1
    H
  • 1
    M
  • 0
    L
11.0.221 May, 2026
  • 0
    C
  • 3
    H
  • 5
    M
  • 0
    L
11.0.2130 Mar, 2026
  • 0
    C
  • 3
    H
  • 6
    M
  • 0
    L
11.0.2022 Mar, 2026
  • 0
    C
  • 3
    H
  • 6
    M
  • 0
    L
11.0.1828 Feb, 2026
  • 0
    C
  • 3
    H
  • 6
    M
  • 0
    L
11.0.1516 Dec, 2025
  • 0
    C
  • 3
    H
  • 6
    M
  • 0
    L
11.0.1416 Dec, 2025
  • 0
    C
  • 3
    H
  • 6
    M
  • 0
    L
11.0.1316 Dec, 2025
  • 0
    C
  • 3
    H
  • 6
    M
  • 0
    L