org.apache.tomcat:tomcat

Licenses: Apache-2.0

Direct Vulnerabilities

Known vulnerabilities in the org.apache.tomcat:tomcat package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Cross-site Scripting (XSS)

[9.0.0.M1,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
  • M
Always-Incorrect Control Flow Implementation

[9.0.0.M1,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
  • M
Always-Incorrect Control Flow Implementation

[9.0.0.M1,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
  • M
Improper Authorization

[9.0.0.M1,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
  • C
Missing Critical Step in Authentication

[9.0.0-M1,9.0.101)[10.1.0-M1,10.1.37)[11.0.0-M1,11.0.5)
  • H
Detection of Error Condition Without Action

[9.0.83,9.0.119)[10.1.0-M7,10.1.56)[11.0.0-M1,11.0.23)
  • H
Improper Authentication

[9.0.13,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
  • M
Timing Attack

[,9.0.118)[10.1.0-M1,10.1.55)[11.0.0-M1,11.0.22)
  • H
Untrusted Search Path

[9.0.23,9.0.106)[10.1.0,10.1.42)[11.0.0-M1,11.0.8)
  • M
Incomplete Cleanup

[8.5.0,8.5.94)[9.0.0-M1,9.0.81)[10.1.0-M1,10.1.14)[11.0.0-M1,11.0.0-M12)
  • M
Improper Input Validation

[8.5.0,8.5.94)[9.0.0-M1,9.0.81)[10.1.0-M1,10.1.14)[11.0.0-M1,11.0.0-M12)
  • M
Incomplete Cleanup

[8.5.85,8.5.94)[9.0.70,9.0.81)
  • M
Access Restriction Bypass

[8.5.0,8.5.93)[9.0.0-M1,9.0.80)[10.1.0-M1,10.1.13)[11.0.0-M1,11.0.0-M11)
  • M
Cross-site Scripting (XSS)

[8.5.50,8.5.82)[9.0.30,9.0.65)[10.0.0-M1,10.0.23)[10.1.0-M1,10.1.0-M17)
  • H
Denial of Service (DoS)

[10.0.0,10.0.4)[8.0.0,8.5.64)[9.0.0,9.0.44)
  • M
Improper Input Validation

[10.0.0-M1,10.0.6)[9.0.0.M1,9.0.46)[8.5.0,8.5.66)[7.0.0,7.0.109)
  • M
HTTP Request Smuggling

[10.0.0-M1,10.0.7)[9.0.0.M1,9.0.48)[8.5.0,8.5.68)
  • H
Denial of Service (DoS)

[10.0.3,10.0.5)[9.0.44,9.0.45)[8.5.64,8.5.65)
  • M
Incorrectly Documented Search Algorithm

[,7.0.84)[8.0.0-RC1,8.0.48)[8.5.0,8.5.24)[9.0.0.M1,9.0.2)
  • H
Improper Access Control

[7.35,8.5.5)
  • H
Cross-site Request Forgery (CSRF)

[7,7.0.68)[8,8.0.31)[9-alpha,9.0.0.M2]
  • M
Insecure Default

[7.0.0,7.0.40)

Package versions

440 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
11.0.243 Jul, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
11.0.2317 Jun, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
11.0.221 May, 2026
  • 0
    C
  • 2
    H
  • 4
    M
  • 0
    L
11.0.2130 Mar, 2026
  • 0
    C
  • 2
    H
  • 5
    M
  • 0
    L
11.0.2022 Mar, 2026
  • 0
    C
  • 2
    H
  • 5
    M
  • 0
    L
11.0.1828 Feb, 2026
  • 0
    C
  • 2
    H
  • 5
    M
  • 0
    L
11.0.1516 Dec, 2025
  • 0
    C
  • 2
    H
  • 5
    M
  • 0
    L
11.0.1416 Dec, 2025
  • 0
    C
  • 2
    H
  • 5
    M
  • 0
    L
11.0.1316 Dec, 2025
  • 0
    C
  • 2
    H
  • 5
    M
  • 0
    L
11.0.1216 Dec, 2025
  • 0
    C
  • 2
    H
  • 5
    M
  • 0
    L