| <!DOCTYPE html SYSTEM "about:legacy-compat"> |
| <html lang="en"><head><META http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" type="text/css"><title>Apache Tomcat® - Apache Tomcat 10 vulnerabilities</title><meta name="author" content="Apache Tomcat Project"><script src="https://www.apachecon.com/event-images/snippet.js"></script></head><body><div id="wrapper"><header id="header"><div class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div class="hamburger"></div></div><a href="http://tomcat.apache.org/"><img class="tomcat-logo pull-left noPrint" alt="Tomcat Home" src="res/images/tomcat.png"></a><h1 class="pull-left">Apache Tomcat<sup>®</sup></h1><div class="asf-logos pull-right"><a href="https://www.apache.org/foundation/contributing.html" target="_blank" class="pull-left"><img src="https://www.apache.org/images/SupportApache-small.png" class="support-asf" alt="Support Apache"></a><a href="http://www.apache.org/" target="_blank" class="pull-left"><img src="res/images/asf_logo_wide.svg" class="asf-logo" alt="The Apache Software Foundation"></a></div></div></header><main id="middle"><div><div id="mainLeft"><div id="nav-wrapper"><form action="https://www.google.com/search" method="get"><div class="searchbox"><input value="tomcat.apache.org" name="sitesearch" type="hidden"><input aria-label="Search text" placeholder="Search…" required="required" name="q" id="query" type="search"><button>GO</button></div></form><div class="asfevents"><a class="acevent" data-format="square" data-width="150"></a></div><nav><div><h2>Apache Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a href="./whichversion.html">Which version?</a></li><li><a href="https://tomcat.apache.org/download-11.cgi">Tomcat 11</a></li><li><a href="https://tomcat.apache.org/download-10.cgi">Tomcat 10</a></li><li><a href="https://tomcat.apache.org/download-90.cgi">Tomcat 9</a></li><li><a href="https://tomcat.apache.org/download-migration.cgi">Tomcat Migration Tool for Jakarta EE</a></li><li><a href="https://tomcat.apache.org/download-connectors.cgi">Tomcat Connectors</a></li><li><a href="https://tomcat.apache.org/download-native.cgi">Tomcat Native</a></li><li><a href="https://tomcat.apache.org/download-taglibs.cgi">Taglibs</a></li><li><a href="https://archive.apache.org/dist/tomcat/">Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a href="./tomcat-11.0-doc/index.html">Tomcat 11.0</a></li><li><a href="./tomcat-10.1-doc/index.html">Tomcat 10.1</a></li><li><a href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a href="./upgrading.html">Upgrading</a></li><li><a href="./connectors-doc/index.html">Tomcat Connectors</a></li><li><a href="./native-doc/index.html">Tomcat Native 2</a></li><li><a href="./native-1.3-doc/index.html">Tomcat Native 1.3</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT">Wiki</a></li><li><a href="./migration.html">Migration Guide</a></li><li><a href="./presentations.html">Presentations</a></li><li><a href="https://cwiki.apache.org/confluence/x/Bi8lBg">Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a href="./security.html">Security Reports</a></li><li><a href="./findhelp.html">Find help</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ">FAQ</a></li><li><a href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug Database</a></li></ul></div><div><h2>Get Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a href="./source.html">Source code</a></li><li><a href="./ci.html">Buildbot</a></li><li><a href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a href="https://www.youtube.com/c/ApacheTomcatOfficial">YouTube</a></li></ul></div><div><h2>Misc</h2><ul><li><a href="./whoweare.html">Who We Are</a></li><li><a href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat">Swag</a></li><li><a href="./heritage.html">Heritage</a></li><li><a href="http://www.apache.org">Apache Home</a></li><li><a href="./resources.html">Resources</a></li><li><a href="./contact.html">Contact</a></li><li><a href="./legal.html">Legal</a></li><li><a href="https://privacy.apache.org/policies/privacy-policy-public.html">Privacy</a></li><li><a href="https://www.apache.org/foundation/contributing.html">Support Apache</a></li><li><a href="https://www.apache.org/foundation/sponsorship.html">Sponsorship</a></li><li><a href="http://www.apache.org/foundation/thanks.html">Thanks</a></li><li><a href="http://www.apache.org/licenses/">License</a></li></ul></div></nav></div></div><div id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 id="Apache_Tomcat_10.x_vulnerabilities">Apache Tomcat 10.x vulnerabilities</h3><div class="text"> |
| <p>This page lists all security vulnerabilities fixed in released versions |
| of Apache Tomcat<sup>®</sup> 10.x. Each vulnerability is given a |
| <a href="security-impact.html">security impact rating</a> by the Apache |
| Tomcat security team — please note that this rating may vary from |
| platform to platform. We also list the versions of Apache Tomcat the flaw |
| is known to affect, and where a flaw has not been verified list the |
| version with a question mark.</p> |
| |
| <p><strong>Note:</strong> Vulnerabilities that are not Tomcat vulnerabilities |
| but have either been incorrectly reported against Tomcat or where Tomcat |
| provides a workaround are listed at the end of this page.</p> |
| |
| <p><strong>Please note that Tomcat 10.0.x has reached |
| <a href="tomcat-10.0-eol.html">end of life</a> and is no longer supported. |
| Vulnerabilities reported after 31 October 2022 were not checked against the |
| 10.0.x branch and will not be fixed. Users should upgrade to 10.1.x or |
| later to obtain security fixes.</strong></p> |
| |
| <p>Please note that binary patches are never provided. If you need to |
| apply a source code patch, use the building instructions for the |
| Apache Tomcat version that you are using. For Tomcat 10.0.x those are |
| <a href="/tomcat-10.0-doc/building.html"><code>building.html</code></a> and |
| <a href="/tomcat-10.0-doc/BUILDING.txt"><code>BUILDING.txt</code></a>. |
| Both files can be found in the <code>webapps/docs</code> subdirectory |
| of a binary distribution. You may also want to review the |
| <a href="/tomcat-10.0-doc/security-howto.html">Security Considerations</a> |
| page in the documentation.</p> |
| |
| <p>If you need help on building or configuring Tomcat or other help on |
| following the instructions to mitigate the known vulnerabilities listed |
| here, please send your questions to the public |
| <a href="lists.html">Tomcat Users mailing list</a> |
| </p> |
| |
| <p>If you have encountered an unlisted security vulnerability or other |
| unexpected behaviour that has <a href="security-impact.html">security |
| impact</a>, or if the descriptions here are incomplete, |
| please report them privately to the |
| <a href="security.html">Tomcat Security Team</a>. Thank you. |
| </p> |
| |
| </div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text"> |
| <ul><li><a href="#Fixed_in_Apache_Tomcat_10.1.59">Fixed in Apache Tomcat 10.1.59</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.57">Fixed in Apache Tomcat 10.1.57</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.56">Fixed in Apache Tomcat 10.1.56</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.55">Fixed in Apache Tomcat 10.1.55</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.54">Fixed in Apache Tomcat 10.1.54</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.53">Fixed in Apache Tomcat 10.1.53</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.52">Fixed in Apache Tomcat 10.1.52</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.50">Fixed in Apache Tomcat 10.1.50</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.47">Fixed in Apache Tomcat 10.1.47</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.45">Fixed in Apache Tomcat 10.1.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.44">Fixed in Apache Tomcat 10.1.44</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.43">Fixed in Apache Tomcat 10.1.43</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.42">Fixed in Apache Tomcat 10.1.42</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.41">Fixed in Apache Tomcat 10.1.41</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.40">Fixed in Apache Tomcat 10.1.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.39">Fixed in Apache Tomcat 10.1.39</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.35">Fixed in Apache Tomcat 10.1.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.34">Fixed in Apache Tomcat 10.1.34</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.33">Fixed in Apache Tomcat 10.1.33</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.31">Fixed in Apache Tomcat 10.1.31</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.25">Fixed in Apache Tomcat 10.1.25</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.19">Fixed in Apache Tomcat 10.1.19</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.16">Fixed in Apache Tomcat 10.1.16</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.14">Fixed in Apache Tomcat 10.1.14</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.13">Fixed in Apache Tomcat 10.1.13</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.9">Fixed in Apache Tomcat 10.1.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.8">Fixed in Apache Tomcat 10.1.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.6">Fixed in Apache Tomcat 10.1.6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.5">Fixed in Apache Tomcat 10.1.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.2">Fixed in Apache Tomcat 10.1.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.1">Fixed in Apache Tomcat 10.1.1</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.27">Fixed in Apache Tomcat 10.0.27</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.23">Fixed in Apache Tomcat 10.0.23</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.0-M17">Fixed in Apache Tomcat 10.1.0-M17</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.21">Fixed in Apache Tomcat 10.0.21</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.0-M15">Fixed in Apache Tomcat 10.1.0-M15</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.20">Fixed in Apache Tomcat 10.0.20</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.0-M14">Fixed in Apache Tomcat 10.1.0-M14</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.16">Fixed in Apache Tomcat 10.0.16</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.0-M10">Fixed in Apache Tomcat 10.1.0-M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.12">Fixed in Apache Tomcat 10.0.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.0-M6">Fixed in Apache Tomcat 10.1.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.7">Fixed in Apache Tomcat 10.0.7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.6">Fixed in Apache Tomcat 10.0.6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.5">Fixed in Apache Tomcat 10.0.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.4">Fixed in Apache Tomcat 10.0.4</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.2">Fixed in Apache Tomcat 10.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M10">Fixed in Apache Tomcat 10.0.0-M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M8">Fixed in Apache Tomcat 10.0.0-M8</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M7">Fixed in Apache Tomcat 10.0.0-M7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M6">Fixed in Apache Tomcat 10.0.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M5">Fixed in Apache Tomcat 10.0.0-M5</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in Tomcat</a></li></ul> |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.59"><span class="pull-right">2026-08-20</span> Fixed in Apache Tomcat 10.1.59</h3><div class="text"> |
| |
| <p><i>Note: The issues below were fixed in Apache Tomcat 10.1.58 but the |
| release vote for the 10.1.58 release candidate did not pass. Therefore, |
| although users must download 10.1.59 to obtain a version that includes a |
| fix for these issues, version 10.1.58 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Low: Authenticated WebSocket session survives end of HTTP |
| session</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73180" rel="nofollow">CVE-2026-73180</a></p> |
| |
| <p>If the session ID for an authenticated HTTP session was changed after a |
| WebSocket connection had been established under that authenticated HTTP |
| session, the WebSokcet session would not be closed as required by the |
| Jakarta WebSocket specification when the HTTP session ended.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/83427cbdb92ca41244dc3d242ca4308ed8ade7d3">83427cbd</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 30 July 2026. |
| The issue was made public on 25 August 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.57</p> |
| |
| <p><strong>Important: DoS via allocation leak in HTTP/2 backlog tracking |
| when a stream is reset</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-68763" rel="nofollow">CVE-2026-68763</a></p> |
| |
| <p>An allocation leak in the HTTP/2 backlog tracking when a stream was reset |
| could be manipulated to trigger a denial of service.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/19d40615620fe145e88536e2bd63c5f01077c253">19d40615</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 16 July 2026. |
| The issue was made public on 25 August 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.57</p> |
| |
| <p><strong>Important: Principal lookup could fail open in some |
| cases</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-68569" rel="nofollow">CVE-2026-68569</a></p> |
| |
| <p>For some authentication methods (e.g. CLIENT-CERT, SPNEGO), a user would |
| be authenticated even if the user did not exist in the |
| DataSourceRealm.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/3ff06ceb984edc2a3c9e0161b01e833c5e50ed4f">3ff06ceb</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 16 July 2026. |
| The issue was made public on 25 August 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.57</p> |
| |
| <p><strong>Low: Redirect after FORM authentication may bypass method |
| specific constraints</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-68525" rel="nofollow">CVE-2026-68525</a></p> |
| |
| <p>The FORM authentication process allowed the bypassing of a security |
| constraint that limited user access to a resource POST but not GET.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/58123aa468a20e2a079b7e0c68a4009e2475c098">58123aa4</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 15 July 2026. |
| The issue was made public on 25 August 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.57</p> |
| |
| <p><strong>Low: Servlet role references can bypass declarative role |
| constraints</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66422" rel="nofollow">CVE-2026-66422</a></p> |
| |
| <p><code>security-role-ref</code> definitions were incorrectly used as role |
| aliases within the Realm in additional to the correct usage with |
| <code>Request.isUserInRole()</code>.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/49506f6d5ad7cdef211ce1a4026a29183b3df5c7">49506f6d</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 13 July 2026. |
| The issue was made public on 25 August 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.57</p> |
| |
| <p><strong>Low: DoS in WebSocket chat example</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66299" rel="nofollow">CVE-2026-66299</a></p> |
| |
| <p>The WebSocket chat example provided an unbounded buffer for undelivered |
| messages. A maliciously slow client could cause the buffer to grow |
| continuously, eventually leading to an memory exhaustion and failure of |
| the Tomcat process.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/446efef55c69b0cabde1f7e582382cb26e651022">446efef5</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 13 July 2026. |
| The issue was made public on 28 July 2026.</p> |
| |
| <p>Affects: 10.1.24 to 10.1.57<br> |
| Users who followed the security guidance to remove the examples web |
| application are not affected.</p> |
| |
| <p><strong>Important: RewriteValve [N] restarts at the second rule and may |
| bypass access control</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65927" rel="nofollow">CVE-2026-65927</a></p> |
| |
| <p>An off-by-one error impacting the [N] flag on the rewrite valves caused |
| rewrite processing to restart at the second rule rather than the first |
| rule.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/3097902177a041a93476a036b9c8419b25d5cc0d">30979021</a> and |
| <a href="https://github.com/apache/tomcat/commit/7d2ae3952a39db5790dcfd36e5d79c75570a20ee">7d2ae395</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 13 July 2026. |
| The issue was made public on 25 August 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.57</p> |
| |
| <p><strong>Low: Limited replay attack possible with DIGEST |
| authentication</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65905" rel="nofollow">CVE-2026-65905</a></p> |
| |
| <p>If, before windowSize requests had been made, a client made a DIGEST |
| authenticated request with a nonceCount on the upper boundary of the |
| replay window then that request was replayable once only while the |
| associated nonceCount remained within the replay window.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/1c1a583ba57092206f77c375f45da12c99fb141d">1c1a583b</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 13 July 2026. |
| The issue was made public on 25 August 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.57</p> |
| |
| <p><strong>Moderate: HTTP/2 no-authority bypass of strict SNI |
| validation</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65637" rel="nofollow">CVE-2026-65637</a></p> |
| |
| <p>The fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32990" rel="nofollow">CVE-2026-32990</a> was incomplete.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/40012414df828a56126f76a7339669c7c919aae7">40012414</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 13 July 2026. |
| The issue was made public on 25 August 2026.</p> |
| |
| <p>Affects: 10.1.53 to 10.1.57</p> |
| |
| <p><strong>Low: TOCTOU when setting specific permissions for Unix Domain |
| Sockets</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65183" rel="nofollow">CVE-2026-65183</a></p> |
| |
| <p>A race condition when creating a Unix Domain Socket allowed an |
| unauthorised local user to access the Unix Domain Socket.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/d8bcec9a30788fd887f33890b77ae1b8cd5f1f7e">d8bcec9a</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 3 July 2026. |
| The issue was made public on 25 August 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.57</p> |
| |
| <p><strong>Important: Security constraint bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65182" rel="nofollow">CVE-2026-65182</a></p> |
| |
| <p>The security constraint processing enabled a security constraint bypass |
| if a constraint for a longer path was specified before a more restrictive |
| constraint for a shorter sub-path.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/b79752d2a8578d94743e2a95c50af297f780c0df">b79752d2</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 13 July 2026. |
| The issue was made public on 25 August 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.57</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.57"><span class="pull-right">2026-07-07</span> Fixed in Apache Tomcat 10.1.57</h3><div class="text"> |
| |
| <p><strong>Low: EncryptInterceptor requirements not clearly |
| documented</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59084" rel="nofollow">CVE-2026-59084</a></p> |
| |
| <p>The requirements to securely configure the EncryptInterceptor were not |
| clearly documented.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/79466463f18cf57704513a5aaa93961bf14c9ef5">79466463</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 29 June 2026. |
| The issue was made public on 14 July 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.56</p> |
| |
| <p><strong>Low: Incorrect URL decoding in RewriteValve may allow security |
| control bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59083" rel="nofollow">CVE-2026-59083</a></p> |
| |
| <p>Incorrect decoding of <code>+</code> in rewritten URIs to a single space |
| could allow security control bypass for some configurations.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/04e9ec3d32209faa26ca6c23ebd9ad514690aec0">04e9ec3d</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 26 June 2026. |
| The issue was made public on 14 July 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.56</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.56"><span class="pull-right">2026-06-22</span> Fixed in Apache Tomcat 10.1.56</h3><div class="text"> |
| |
| <p><strong>Moderate: Security constraints for default servlet ignored |
| method</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55956" rel="nofollow">CVE-2026-55956</a></p> |
| |
| <p>If security constraints were specified for the default servlet, any |
| method or method omission configured as part of the constraint was |
| ignored.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/9c3b1efb74fd04f77639720af1d48a8f664ad9bb">9c3b1efb</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 15 June 2026. |
| The issue was made public on 29 June 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.55</p> |
| |
| <p><strong>Low: EncryptInterceptor not protected against replay |
| attacks</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55955" rel="nofollow">CVE-2026-55955</a></p> |
| |
| <p>Contrary to the documentation, the EncryptInterceptor was not protected |
| against replay attacks.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/3a9ff01d2dfaca651edacbda3260e37b98b540d3">3a9ff01d</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 17 June 2026. |
| The issue was made public on 29 June 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.55</p> |
| |
| <p><strong>Low: Logged effective web.xml is incomplete</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55276" rel="nofollow">CVE-2026-55276</a></p> |
| |
| <p>Logic errors in the effective web.xml generation meant that neither |
| special roles nor empty authorization constraints were included in the |
| logged effective web.xml.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/25677f90fd721c26ef0f613d34ef8275b1aafc31">25677f90</a> and |
| <a href="https://github.com/apache/tomcat/commit/17daf80a738d66a8e6cad05c5e32c2db81500ce1">17daf80a</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 16 June 2026. |
| The issue was made public on 29 June 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.55</p> |
| |
| <p><strong>Low: Invalid CRL configuration doesn't trigger failure for FFM |
| Connector</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-53434" rel="nofollow">CVE-2026-53434</a></p> |
| |
| <p>If an FFM connector was configured with invalid CRLs, the invalid CRLs |
| were ignored meaning invalid certificates could be accepted.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/feec60d6099727db6f911534f6a0f6926ebab070">feec60d6</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 8 June 2026. |
| The issue was made public on 29 June 2026.</p> |
| |
| <p>Affects: 10.1.0-M7 to 10.1.55</p> |
| |
| <p><strong>Low: Bad ornext processing in RewriteValve</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-53404" rel="nofollow">CVE-2026-53404</a></p> |
| |
| <p>If a request matched the first condition in an OR chain, subsequent |
| non-OR conditions were skipped and the rewrite succeeded.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/bbb6219fa5ac185060bef7842cee5fb90230ca00">bbb6219f</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 28 May 2026. |
| The issue was made public on 29 June 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.55</p> |
| |
| <p><strong>Low: XSS in number guess example</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50229" rel="nofollow">CVE-2026-50229</a></p> |
| |
| <p>The use of wild card property mapping resulted in some properties, that |
| were intended to be internal only, being exposed to clients allowing an |
| XSS attack.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/0d5bdd5b0dd964e9f73e530b7d753462b9bfd1d0">0d5bdd5b</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 11 May 2026. |
| The issue was made public on 29 June 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.55</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.55"><span class="pull-right">2026-05-11</span> Fixed in Apache Tomcat 10.1.55</h3><div class="text"> |
| |
| <p><strong>Moderate: Security constraints not correctly applied</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43515" rel="nofollow">CVE-2026-43515</a></p> |
| |
| <p>When multiple security constraints defined an HTTP method constraint for |
| the same extension pattern, only the first method constraint was |
| applied.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/c621317382682206fb58ab92ebd3e1b6fdd10ce9">c6213173</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 20 April 2026. |
| The issue was made public on 12 May 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.54</p> |
| |
| <p><strong>Low: AJP secret compared in non-constant time</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43514" rel="nofollow">CVE-2026-43514</a></p> |
| |
| <p>The AJP secret was compared in non-constant time allowing an attacker on |
| the local network to mount a timing attack to determine the AJP |
| secret.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/a102a2a157868ca51d83eaf5a119ccd9976a113e">a102a2a1</a> and |
| <a href="https://github.com/apache/tomcat/commit/a90c358400c133b6173c6b26591923bf814a8508">a90c3584</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 20 April 2026. |
| The issue was made public on 12 May 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.54</p> |
| |
| <p><strong>Low: LockOutRealm treats user names as case-sensitive</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43513" rel="nofollow">CVE-2026-43513</a></p> |
| |
| <p>The LockOut Realm treated user names as case sensitive meaning that, for |
| Realms where the user name was case insensitive, the LockOut Realm was |
| not as effective at blocking brute force attacks against a user's |
| password.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/4a90d3fa93988c447cd5bb7482f76ff70d7f15c2">4a90d3fa</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 20 April 2026. |
| The issue was made public on 12 May 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.54</p> |
| |
| <p><strong>Moderate: Digest authenticator will authenticate any unknown user</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43512" rel="nofollow">CVE-2026-43512</a></p> |
| |
| <p>When DIGEST authentication was configured, any user not known to the |
| configured Realm would be authenticated if they presented the password |
| "null".</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/3d4d3fae07a6cd9c2eb193c5491001740ec64448">3d4d3fae</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 20 April 2026. |
| The issue was made public on 12 May 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.54</p> |
| |
| <p><strong>Low: WebSocket authentication header exposure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42498" rel="nofollow">CVE-2026-42498</a></p> |
| |
| <p>If a WebSocket request was redirected after authentication, Tomcat's |
| WebSocket client would present the most recent authentication header to |
| the redirect target host.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/6cbe274592ef2d11607b5b188e1df649de52f8d5">6cbe2745</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 21 April 2026. |
| The issue was made public on 12 May 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.54</p> |
| |
| <p><strong>Low: HTTP/2 request headers not validated</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41293" rel="nofollow">CVE-2026-41293</a></p> |
| |
| <p>HTTP/2 request headers were not validated which may have triggered |
| unexpected application behaviour if the application (quite reasonably) |
| assumed that header value exposed through the Servlet API would be |
| specification compliant.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/19f17a257797e8d139b33ff9c88d362a273be148">19f17a25</a>, |
| <a href="https://github.com/apache/tomcat/commit/f72a6174ab1f0f5a053435f80448b4f6837fe6d7">f72a6174</a> and |
| <a href="https://github.com/apache/tomcat/commit/2a2476460e823789f530a22207873ea8cd6eff3b">2a247646</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 15 April 2026. |
| The issue was made public on 12 May 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.54</p> |
| |
| <p><strong>Low: Unbounded read in WebDAV LOCK and PROPFIND handling</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41284" rel="nofollow">CVE-2026-41284</a></p> |
| |
| <p>No limit was enforced on the request body for WebDAV LOCK or PROPFIND |
| requests which were available to unauthenticated users.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/b3d1c1c239142e806be0b7329d304b94a58913ed">b3d1c1c2</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 11 April 2026. |
| The issue was made public on 12 May 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.54</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.54"><span class="pull-right">2026-04-02</span> Fixed in Apache Tomcat 10.1.54</h3><div class="text"> |
| |
| <p><strong>Moderate: OCSP checks sometimes soft-fail with FFM even when |
| soft-fail is disabled</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34500" rel="nofollow">CVE-2026-34500</a></p> |
| |
| <p>CLIENT_CERT authentication does not fail as expected for some scenarios |
| when soft fail is disabled and FFM is used.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/29b56a56ce9e7d044b6162a99af0f38529b3a208">29b56a56</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 25 March 2026. |
| The issue was made public on 9 April 2026.</p> |
| |
| <p>Affects: 10.1.22 to 10.1.53</p> |
| |
| <p><strong>Low: Cloud membership for clustering component exposed the |
| Kubernetes bearer token</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34487" rel="nofollow">CVE-2026-34487</a></p> |
| |
| <p>The cloud membership for clustering component exposed the Kubernetes |
| bearer token in log messages.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/5eff2a773b8b728083e5195b3183df1b9e12a03d">5eff2a77</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 25 March 2026. |
| The issue was made public on 9 April 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.53</p> |
| |
| <p><strong>Important: The fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29146" rel="nofollow">CVE-2026-29146</a> allowed the |
| bypass of the EncryptInterceptor</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34486" rel="nofollow">CVE-2026-34486</a></p> |
| |
| <p>An error in the fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29146" rel="nofollow">CVE-2026-29146</a> allowed the |
| EncryptInterceptor to be bypassed.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/55f3eb9148233054fccfdf761141c6894a050be1">55f3eb91</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 26 March 2026. |
| The issue was made public on 9 April 2026.</p> |
| |
| <p>Affects: 10.1.53</p> |
| |
| <p><strong>Low: Incomplete escaping of JSON access logs</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34483" rel="nofollow">CVE-2026-34483</a></p> |
| |
| <p>Incomplete escaping when non-default values were used for the Connector |
| attributes relaxedPathChars and/or relaxedQueryChars allowed the |
| injection of arbitrary JSON into the JSON access log.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/f22dc2ce6cfda8609ed86816c0d78e1a9cbadb06">f22dc2ce</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 25 March 2026. |
| The issue was made public on 9 April 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.53</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.53"><span class="pull-right">2026-03-23</span> Fixed in Apache Tomcat 10.1.53</h3><div class="text"> |
| |
| <p><strong>Moderate: The fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66614" rel="nofollow">CVE-2025-66614</a> was |
| incomplete</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32990" rel="nofollow">CVE-2026-32990</a></p> |
| |
| <p>The validation of SNI name and host name did not take account of possible |
| differences in case allowing the strict SNI checks to be bypassed.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/4d0615a5c718c260d6d4e0b944a050f09a490c02">4d0615a5</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 13 March 2026. |
| The issue was made public on 9 April 2026.</p> |
| |
| <p>Affects: 10.1.50 to 10.1.52</p> |
| |
| <p><strong>Important: EncryptInterceptor vulnerable to padding oracle attack |
| by default</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29146" rel="nofollow">CVE-2026-29146</a></p> |
| |
| <p>The EncryptInterceptor used CBC by default which is vulnerable to a |
| padding Oracle attack.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/607ebc0fa522bd9e8c05517baa2d179bbd1e659c">607ebc0f</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 22 February 2026. |
| The issue was made public on 9 April 2026.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.1.52</p> |
| |
| <p><strong>Moderate: OCSP checks sometimes soft-fail even when soft-fail is |
| disabled</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29145" rel="nofollow">CVE-2026-29145</a></p> |
| |
| <p>CLIENT_CERT authentication did not fail OCSP checks as expected for some |
| scenarios when soft fail was disabled.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/fe26667cd2385045ac73f4dea086cc9971209b90">fe26667c</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 26 February 2026. |
| The issue was made public on 9 April 2026.</p> |
| |
| <p><strong>Low: Configured TLS cipher preference order not preserved</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29129" rel="nofollow">CVE-2026-29129</a></p> |
| |
| <p>The additional of the ability to configure TLS 1.3 cipher suites did not |
| preserve the order of the configured cipher suites and ciphers.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/8d69b33764dba81dce89e3a768de6093a35620ae">8d69b337</a>.</p> |
| |
| <p>This was reported as a bug on 20 February 026 and the security |
| implications identified by the Tomcat security team the same day. |
| The issue was made public on 9 April 2026.</p> |
| |
| <p>Affects: 10.1.51 to 10.1.52</p> |
| |
| <p><strong>Low: Occasionally open redirect</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25854" rel="nofollow">CVE-2026-25854</a></p> |
| |
| <p>When a Tomcat node in a cluster with the LoadBalancerDrainingValve was in |
| the disabled (draining) state, a specially crafted URL could be used to |
| trigger a redirect to a URI of the attackers choice.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/5fb910f9a9dafa37a0c0965a1bd62a21dcf437f2">5fb910f9</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 30 January 2026. |
| The issue was made public on 9 April 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.52</p> |
| |
| <p><strong>Low: Request smuggling via invalid chunk extension</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24880" rel="nofollow">CVE-2026-24880</a></p> |
| |
| <p>Tomcat did not validate that contents of HTTP/1.1 chunk extensions. This |
| enabled a request smuggling attack if a reverse proxy in front of Tomcat |
| allowed CRLF sequences in an otherwise valid chunk extension.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/f07df938d00f7419b40fa65aa912966d0efac522">f07df938</a> and |
| <a href="https://github.com/apache/tomcat/commit/1e71441a15972f56e661b0b549fb9e5d838b83bb">1e71441a</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 19 January 2026. |
| The issue was made public on 9 April 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.52</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.52"><span class="pull-right">2026-01-27</span> Fixed in Apache Tomcat 10.1.52</h3><div class="text"> |
| |
| <p><strong>Moderate: Incomplete OCSP verification checks</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24734" rel="nofollow">CVE-2026-24734</a></p> |
| |
| <p>When using an OCSP responder, Tomcat's FFM integration with OpenSSL did |
| not complete verification or freshness checks on the OCSP response which |
| could allow certificate revocation to be bypassed.</p> |
| |
| <p>Affects: 10.1.0-M7 to 10.1.51</p> |
| |
| <p>This issue was reported to the Tomcat security team on 2 November 2025. |
| The issue was made public on 17 February 2026.</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.50"><span class="pull-right">2025-12-08</span> Fixed in Apache Tomcat 10.1.50</h3><div class="text"> |
| |
| <p><strong>Low: Security constraint bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24733" rel="nofollow">CVE-2026-24733</a></p> |
| |
| <p>Tomcat did not limit HTTP/0.9 requests to the GET method. If a security |
| constraint was configured to allow HEAD requests to a URI but deny GET |
| requests, the user could bypass that constraint on GET requests by |
| sending a (specification invalid) HEAD request using HTTP/0.9.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/711b465cf22684a1acf0cb43501cdbbce9b6c5f4">711b465c</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 26 November |
| 2025. The issue was made public on 17 February 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.49</p> |
| |
| <p><strong>Moderate: Client certificate verification bypass due to virtual |
| host mapping</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66614" rel="nofollow">CVE-2025-66614</a></p> |
| |
| <p>Tomcat did not validate that the host name provided via the SNI extension |
| was the same as the host name provided in the HTTP host header field. If |
| Tomcat was configured with more than one virtual host and the TLS |
| configuration for one of those hosts did not require client certificate |
| authentication but another one did, it was possible for a client to |
| bypass the client certificate authentication by sending different host |
| names in the SNI extension and the HTTP host header field.</p> |
| |
| <p>The vulnerability only applies if client certificate authentication is |
| only enforced at the Connector. It does not apply if client certificate |
| authentication is enforced at the web application.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/972f9a5e2a07674d92610c478aac1b205d60724e">972f9a5e</a> and |
| <a href="https://github.com/apache/tomcat/commit/5053fa82a1b2b52756810601227984a8b71888a4">5053fa82</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 15 October 2025. |
| The issue was made public on 17 February 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.49</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.47"><span class="pull-right">2025-10-07</span> Fixed in Apache Tomcat 10.1.47</h3><div class="text"> |
| |
| <p><strong>Low: Delayed cleaning of multipart upload temporary files may |
| lead to DoS</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61795" rel="nofollow">CVE-2025-61795</a></p> |
| |
| <p>If an error occurred (including exceeding limits) during the processing |
| of a multipart upload, temporary copies of the uploaded parts written to |
| local storage were not cleaned up immediately but left for the garbage |
| collection process to delete. Depending on JVM settings, application |
| memory usage and application load, it was possible that space for the |
| temporary copies of uploaded parts would be filled faster than GC cleared |
| it, leading to a DoS.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/af6e9181620304c0d818121c29c074e1330610d0">af6e9181</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 7 September 2025. |
| The issue was made public on 27 October 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.46</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.45"><span class="pull-right">2025-09-08</span> Fixed in Apache Tomcat 10.1.45</h3><div class="text"> |
| |
| <p><strong>Low: Console manipulation via escape sequences in log |
| messages</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55754" rel="nofollow">CVE-2025-55754</a></p> |
| |
| <p>Tomcat did not escape ANSI escape sequences in log messages. If Tomcat |
| was running in a console on a Windows operating system, and the console |
| supported ANSI escape sequences, it was possible for an attacker to use a |
| specially crafted URL to inject ANSI escape sequences to manipulate the |
| console and the clipboard and attempt to trick an administrator into |
| running an attacker controlled command. While no attack vector was found, |
| it may have been possible to mount this attack on other operating |
| systems.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/138d7f5cfaae683078948303333c080e6faa75d2">138d7f5c</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 5 August 2025. The |
| issue was made public on 27 October 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.44</p> |
| |
| <p><strong>Important: Directory traversal via Rewrite Valve with possible |
| remote code execution if PUT is enabled</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55752" rel="nofollow">CVE-2025-55752</a></p> |
| |
| <p>The fix for bug <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=60013">60013</a> introduced a regression where the |
| rewritten URL was normalized before it was decoded. This introduced the |
| possibility that, for rewrite rules that rewrite query parameters to the |
| URL, an attacker could manipulate the request URI to bypass security |
| constraints including the protection for <code>/WEB-INF/</code> and |
| <code>/META-INF/</code>. If PUT requests were also enabled then malicious |
| files could be uploaded leading to remote code execution. PUT requests |
| are normally limited to trusted users and it is considered unlikely that |
| PUT requests would be enabled in conjunction with a rewrite that |
| manipulated the URI.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/130d36d8492ef9e4eb22952c17c92423cb35fd06">130d36d8</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 11 August 2025. |
| The issue was made public on 27 October 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.44</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.44"><span class="pull-right">2025-08-07</span> Fixed in Apache Tomcat 10.1.44</h3><div class="text"> |
| |
| <p><strong>Important: DoS in HTTP/2 due to client triggered stream |
| reset</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48989" rel="nofollow">CVE-2025-48989</a></p> |
| |
| <p>Tomcat's HTTP/2 implementation was vulnerable to the made you reset |
| attack. The denial of service typically manifested as an |
| <code>OutOfMemoryError</code>.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/73c04a10395774bda71a0b37802cf983662ce255">73c04a10</a>.</p> |
| |
| <p>This issue was reported to the ASF security team on 29 May 2025. The |
| issue was made public on 13 August 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.43</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.43"><span class="pull-right">2025-07-04</span> Fixed in Apache Tomcat 10.1.43</h3><div class="text"> |
| |
| <p><strong>Low: DoS due to overflow in file upload limit</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52520" rel="nofollow">CVE-2025-52520</a></p> |
| |
| <p>For some unlikely configurations of multipart upload, an Integer Overflow |
| vulnerability could lead to a DoS via bypassing of size limits.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/fc42bbccb9041fafd194fbfdf3eab1d44cb5c45c">fc42bbcc</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 7 June 2025. The |
| issue was made public on 10 July 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.42</p> |
| |
| <p><strong>Important: DoS via excessive HTTP/2 streams</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-53506" rel="nofollow">CVE-2025-53506</a></p> |
| |
| <p>An uncontrolled resource consumption vulnerability if an HTTP/2 client |
| did not acknowledge the initial settings frame that reduces the maximum |
| permitted concurrent streams could result in a DoS.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/2aa6261276ebe50b99276953591e3a2be7898bdb">2aa62612</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 28 June 2025. The |
| issue was made public on 10 July 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.42</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.42"><span class="pull-right">2025-06-09</span> Fixed in Apache Tomcat 10.1.42</h3><div class="text"> |
| |
| <p><strong>Moderate: Session fixation possible via rewrite valve</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55668" rel="nofollow">CVE-2025-55668</a></p> |
| |
| <p>If the rewrite valve was enabled for a web application, an attacker was |
| able to craft a URL that, if a victim clicked on it, would cause the |
| victim's interaction with that resource to occur in the context of the |
| attacker's session.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/8621e4c6ba2c916a41eb34cb0f781171ead33fb6">8621e4c6</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 30 May 2025. The |
| issue was made public on 13 August 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.41</p> |
| |
| <p><strong>Moderate: Security constraint bypass for PreResources and |
| PostResources</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-49125" rel="nofollow">CVE-2025-49125</a></p> |
| |
| <p>When using PreResources or PostResources mounted other than at the root |
| of the web application, it was possible to access those resources via an |
| unexpected path. That path was likely not to be protected by the same |
| security constraints as the expected path, allowing those security |
| constraints to be bypassed.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/7617b9c247bc77ed0444dd69adcd8aa48777886c">7617b9c2</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 30 May 2025. The |
| issue was made public on 16 June 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.41</p> |
| |
| <p><strong>Low: Side-loading via Tomcat installer for Windows</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-49124" rel="nofollow">CVE-2025-49124</a></p> |
| |
| <p>During installation, the Tomcat installer for Windows used icacls.exe |
| without specifying a full path. This enabled a side-loading |
| vulnerability.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/e0e07812224d327a321babb554f5a5758d30cc49">e0e07812</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 30 May 2025. The |
| issue was made public on 16 June 2025.</p> |
| |
| <p>Affects: 10.1.0 to 10.1.41</p> |
| |
| <p><strong>Important: DoS in multipart upload</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48988" rel="nofollow">CVE-2025-48988</a></p> |
| |
| <p>Tomcat used the same limit for both request parameters and parts in a |
| multipart request. Since uploaded parts also include headers which must |
| be retained, processing multipart requests can result in significantly |
| more memory usage. A specially crafted request that used a large number |
| of parts could trigger excessive memory usage leading to a DoS. The |
| maximum number of parts is now configurable (maxPartCount on the |
| Connector) with a default of 10 parts.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/cdde8e655bc1c5c60a07efd216251d77c52fd7f6">cdde8e65</a>.</p> |
| |
| <p>This issue was reported to the ASF security team on 16 May 2025. The |
| issue was made public on 16 June 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.41</p> |
| |
| <p><strong>Important: DoS in Commons FileUpload</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48976" rel="nofollow">CVE-2025-48976</a></p> |
| |
| <p>Apache Commons FileUpload provided a hard-coded limit of 10kB for the |
| size of the headers associated with a multipart request. A specially |
| crafted request that used a large number of parts with large headers |
| could trigger excessive memory usage leading to a DoS. This limit is |
| now configurable (maxPartHeaderSize on the Connector) with a default of |
| 512 bytes.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/667ddd76e2a0e762f3a784d86f0d25e7fd7cdb86">667ddd76</a>.</p> |
| |
| <p>This issue was reported to the ASF security team on 16 May 2025. The |
| issue was made public on 16 June 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.41</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.41"><span class="pull-right">2025-05-12</span> Fixed in Apache Tomcat 10.1.41</h3><div class="text"> |
| |
| <p><strong>Low: CGI security constraint bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-46701" rel="nofollow">CVE-2025-46701</a></p> |
| |
| <p>When running on a case insensitive file system with security constraints |
| configured for the <code>pathInfo</code> component of a URL that mapped |
| to the CGI servlet, it was possible to bypass those security constraints |
| with a specially crafted URL.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/2c6800111e7d8d8d5403c07978ea9bff3db5a5a5">2c680011</a> and |
| <a href="https://github.com/apache/tomcat/commit/238d2aa54b99f91d1111467e2237d2244c64e558">238d2aa5</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 7 April 2025. The |
| issue was made public on 29 May 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.40</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.40"><span class="pull-right">2025-04-08</span> Fixed in Apache Tomcat 10.1.40</h3><div class="text"> |
| |
| <p><strong>Low: Rewrite rule bypass</strong> <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-31651" rel="nofollow">CVE-2025-31651</a></p> |
| |
| <p>For a subset of unlikely rewrite rule configurations, it was possible for |
| a specially crafted request to bypass some rewrite rules. If those |
| rewrite rules effectively enforced security constraints, those |
| constraints could be bypassed.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/066bf6b6a15a4e7e0941d4acf096841165b97098">066bf6b6</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 28 February 2025. |
| The issue was made public on 28 April 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.39</p> |
| |
| <p><strong>Important: Denial of Service via invalid HTTP priority |
| header</strong> <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-31650" rel="nofollow">CVE-2025-31650</a></p> |
| |
| <p>Incorrect error handling for some invalid HTTP priority headers resulted |
| in incomplete clean-up of the failed request which created a memory leak. |
| A large number of such requests could trigger an |
| OutOfMemoryException resulting in a denial of service.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/cba1a0fe1289ee7f5dd46c61c38d1e1ac5437bff">cba1a0fe</a>, |
| <a href="https://github.com/apache/tomcat/commit/1eef1dc459c45f1e421d8bd25ef340fc1cc34edc">1eef1dc4</a> and |
| <a href="https://github.com/apache/tomcat/commit/8cc3b8fb3f2d8d4d6a757e014f19d1fafa948a60">8cc3b8fb</a>.</p> |
| |
| <p>This issue was not disclosed responsibly. It was reported via the public |
| bug tracker on 13 March 2025. The CVE was published on 28 April 2025.</p> |
| |
| <p>Affects: 10.1.10 to 10.1.39</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.39"><span class="pull-right">2025-03-07</span> Fixed in Apache Tomcat 10.1.39</h3><div class="text"> |
| |
| <p><strong>Important: Authentication bypass with JNDIRealm and GSSAPI |
| authenticated bind</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55957" rel="nofollow">CVE-2026-55957</a></p> |
| |
| <p>When the JNDIRealm was configured to authenticate binds using GSSAPI, an |
| attacker was able authenticate without providing the correct |
| password.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/0cd21c0393b8811af22daddbba7b4e7328e2d79e">0cd21c03</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 14 June 2026. |
| The issue was made public on 29 June 2026.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.36</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.35"><span class="pull-right">2025-02-10</span> Fixed in Apache Tomcat 10.1.35</h3><div class="text"> |
| |
| <p><strong>Important: Remote Code Execution and/or Information disclosure |
| and/or malicious content added to uploaded files via write enabled |
| Default Servlet - </strong> <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24813" rel="nofollow">CVE-2025-24813</a></p> |
| |
| <p>The original implementation of partial PUT used a temporary file based on |
| the user provided file name and path with the path separator replaced by |
| ".".</p> |
| |
| <p>If all of the following were true, a malicious user was able to view |
| security sensitive files and/or inject content into those files:</p> |
| |
| <ul> |
| <li>writes enabled for the default servlet (disabled by default)</li> |
| <li>support for partial PUT (enabled by default)</li> |
| <li>a target URL for security sensitive uploads that is a sub-directory of |
| a target URL for public uploads</li> |
| <li>attacker knowledge of the names of security sensitive files being |
| uploaded</li> |
| <li>the security sensitive files also being uploaded via partial PUT</li> |
| </ul> |
| |
| <p>If all of the following were true, a malicious user was able to perform |
| remote code execution:</p> |
| |
| <ul> |
| <li>writes enabled for the default servlet (disabled by default)</li> |
| <li>support for partial PUT (enabled by default)</li> |
| <li>application was using Tomcat's file based session persistence with the |
| default storage location</li> |
| <li>application included a library that may be leveraged in a |
| deserialization attack</li> |
| </ul> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc">f6c01d65</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 13 January 2025. |
| The issue was made public on 10 March 2025.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.34</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.34"><span class="pull-right">2024-12-09</span> Fixed in Apache Tomcat 10.1.34</h3><div class="text"> |
| |
| <p><strong>Important: Remote Code Execution via write enabled Default |
| Servlet. Mitigation for CVE-2024-50379 was incomplete - </strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-56337" rel="nofollow">CVE-2024-56337</a></p> |
| |
| <p>The previous mitigation for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50379" rel="nofollow">CVE-2024-50379</a> was incomplete. In |
| addition to upgrading to 10.1.34 or later, users running Tomcat on a case |
| insensitive file system with the default servlet write enabled may need |
| additional configuration depending on the version of Java being used: |
| <ul> |
| <li>running on Java 11: the system property |
| <code>sun.io.useCanonCaches</code> must be explicitly set to |
| <code>false</code> (it defaults to <code>true</code>)</li> |
| <li>running on Java 17: the system property |
| <code>sun.io.useCanonCaches</code>, if set, must be set to |
| <code>false</code> (it defaults to <code>false</code>)</li> |
| <li>running on Java 21 onwards: no further configuration is required (the |
| system property and the problematic cache have been removed)</li> |
| </ul></p> |
| |
| <p>This issue was reported to the Tomcat security team on 17 December 2024. |
| The issue was made public on 20 December 2024.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.33</p> |
| |
| <p><strong>Low: DoS in examples web application</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-54677" rel="nofollow">CVE-2024-54677</a></p> |
| |
| <p>Numerous examples in the examples web application did not place limits on |
| uploaded data enabling an OutOfMemoryError to be triggered causing a |
| denial of service.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/f57a9d9847c1038be61f5818d73b8be907c460d4">f57a9d98</a>, |
| <a href="https://github.com/apache/tomcat/commit/aa5b4d0043289cf054f531ec55126c980d3572e1">aa5b4d00</a>, |
| <a href="https://github.com/apache/tomcat/commit/e8c16cdba833884e1bd49fff1f1cb699da177585">e8c16cdb</a>, |
| <a href="https://github.com/apache/tomcat/commit/dbec927859d9484cb8bd680a7c67b1a560f48444">dbec9278</a>, |
| <a href="https://github.com/apache/tomcat/commit/d63a10afc142b12f462a15f7d10f79fd80ff94eb">d63a10af</a>, |
| <a href="https://github.com/apache/tomcat/commit/54e56495e9a106218efe9fc9c79d976c0032bbfd">54e56495</a> and |
| <a href="https://github.com/apache/tomcat/commit/bbd82e9593314ade4cfd57248f9285fbad686f66">bbd82e95</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 23 November 2024. |
| The issue was made public on 17 December 2024.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.33</p> |
| |
| <p><strong>Important: Remote Code Execution via write enabled Default Servlet</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50379" rel="nofollow">CVE-2024-50379</a></p> |
| |
| <p>If the default servlet is write enabled (<code>readonly</code> |
| initialisation parameter set to the non-default value of |
| <code>false</code>) for a case insensitive file system, concurrent read |
| and upload under load of the same file can bypass Tomcat's case |
| sensitivity checks and cause an uploaded file to be treated as a JSP |
| leading to remote code execution.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/8554f6b1722b33a2ce8b0a3fad37825f3a75f2d2">8554f6b1</a> and |
| <a href="https://github.com/apache/tomcat/commit/05ddeeaa54df1e2dc427d0164bedd6b79f78d81f">05ddeeaa</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 18 October 2024. |
| The issue was made public on 17 December 2024.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.33</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.33"><span class="pull-right">2024-11-11</span> Fixed in Apache Tomcat 10.1.33</h3><div class="text"> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 10.1.32 but the |
| release vote for the 10.1.32 release candidate did not pass. Therefore, |
| although users must download 10.1.33 to obtain a version that includes a |
| fix for these issues, version 10.1.32 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Important: XSS in generated JSPs</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52318" rel="nofollow">CVE-2024-52318</a></p> |
| |
| <p>The fix for improvement <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=69333">69333</a> caused pooled JSP tags not to be |
| released after use which in turn could cause output of some tags not to |
| escaped as expected. This unescaped output could lead to XSS.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/be8e32143a3159e78fe5463d09bb8e1b33bf2b1f">be8e3214</a>.</p> |
| |
| <p>This issue was not disclosed responsibly. It was reported via the public |
| bug tracker on 6 November 2024. The CVE was published on 18 November |
| 2024.</p> |
| |
| <p>Affects: 10.1.31</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.31"><span class="pull-right">2024-10-09</span> Fixed in Apache Tomcat 10.1.31</h3><div class="text"> |
| |
| <p><strong>Important: Request and/or response mix-up</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52317" rel="nofollow">CVE-2024-52317</a></p> |
| |
| <p>Incorrect recycling of the request and response used by HTTP/2 requests |
| could lead to request and/or response mix-up between users.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/146f94f87ea398fb592c7a20a5ccbef95e9dd72b">146f94f8</a>.</p> |
| |
| <p>This issue was identified by the Tomcat Security Team on 1 October 2024. |
| The issue was made public on 18 November 2024.</p> |
| |
| <p>Affects: 10.1.27 to 10.1.30</p> |
| |
| <p><strong>Low: Authentication Bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52316" rel="nofollow">CVE-2024-52316</a></p> |
| |
| <p>If Tomcat was configured to use a custom Jakarta Authentication (formerly |
| JASPIC) ServerAuthContext component which may throw an exception during |
| the authentication process without explicitly setting an HTTP status to |
| indicate failure, the authentication may not have failed, allowing the |
| user to bypass the authentication process. There are no known Jakarta |
| Authentication components that behave in this way.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/acc2f01395f895980f5d8a64573fcc1bade13369">acc2f013</a>.</p> |
| |
| <p>This issue was identified by the Tomcat Security Team on 19 September |
| 2024. The issue was made public on 18 November 2024.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.30</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.25"><span class="pull-right">2024-06-19</span> Fixed in Apache Tomcat 10.1.25</h3><div class="text"> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34750" rel="nofollow">CVE-2024-34750</a></p> |
| |
| <p>When processing an HTTP/2 stream, Tomcat did not handle some cases of |
| excessive HTTP headers correctly. This led to a miscounting of active |
| HTTP/2 streams which in turn led to the use of an incorrect infinite |
| timeout which allowed connections to remain open which should have been |
| closed.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/2afae300c9ac9c0e516e2e9de580847d925365c3">2afae300</a>.</p> |
| |
| <p>This issue was reported to the Tomcat Security Team on 4 May 2024. The |
| issue was made public on 3 July 2024.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.24</p> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38286" rel="nofollow">CVE-2024-38286</a></p> |
| |
| <p>Tomcat, under certain configurations on any platform, allows an attacker |
| to cause an OutOfMemoryError by abusing the TLS handshake process.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/3344c17cef094da4bb616f4186ed32039627b543">3344c17c</a>.</p> |
| |
| <p>This issue was reported to the Tomcat Security Team on 4 June 2024. The |
| issue was made public on 23 September 2024.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.24</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.19"><span class="pull-right">2024-02-19</span> Fixed in Apache Tomcat 10.1.19</h3><div class="text"> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23672" rel="nofollow">CVE-2024-23672</a></p> |
| |
| <p>It was possible for a WebSocket client to keep a WebSocket connection |
| open leading to increased resource consumption.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/0052b374684b613b0c849899b325ebe334ac6501">0052b374</a>.</p> |
| |
| <p>This issue was identified by the Tomcat Security Team on 17 January 2024. |
| The issue was made public on 13 March 2024.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.18</p> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24549" rel="nofollow">CVE-2024-24549</a></p> |
| |
| <p>When processing an HTTP/2 request, if the request exceeded any of the |
| configured limits for headers, the associated HTTP/2 stream was not reset |
| until after all of the headers had been processed.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/d07c82194edb69d99b438828fe2cbfadbb207843">d07c8219</a>.</p> |
| |
| <p>This issue was reported to the Tomcat Security Team on 24 January 2024. The |
| issue was made public on 13 March 2024.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.18</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.16"><span class="pull-right">2023-11-14</span> Fixed in Apache Tomcat 10.1.16</h3><div class="text"> |
| |
| <p><strong>Important: Request smuggling</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46589" rel="nofollow">CVE-2023-46589</a></p> |
| |
| <p>Tomcat did not correctly parse HTTP trailer headers. A specially crafted |
| trailer header that exceeded the header size limit could cause Tomcat to |
| treat a single request as multiple requests leading to the possibility of |
| request smuggling when behind a reverse proxy.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/b5776d769bffeade865061bc8ecbeb2b56167b08">b5776d76</a>.</p> |
| |
| <p>This issue was reported to the Tomcat Security Team on 20 October 2023. |
| The issue was made public on 28 November 2023.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.15</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.14"><span class="pull-right">2023-10-10</span> Fixed in Apache Tomcat 10.1.14</h3><div class="text"> |
| |
| <p><strong>Important: Request smuggling</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45648" rel="nofollow">CVE-2023-45648</a></p> |
| |
| <p>Tomcat did not correctly parse HTTP trailer headers. A specially crafted, |
| invalid trailer header could cause Tomcat to treat a single request as |
| multiple requests leading to the possibility of request smuggling when |
| behind a reverse proxy.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/8ecff306507be8e4fd3adee1ae5de1ea6661a8f4">8ecff306</a>.</p> |
| |
| <p>This issue was reported to the Tomcat Security Team on 12 September 2023. |
| The issue was made public on 10 October 2023.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.13</p> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44487" rel="nofollow">CVE-2023-44487</a></p> |
| |
| <p>Tomcat's HTTP/2 implementation was vulnerable to the rapid reset |
| attack. The denial of service typically manifested as an |
| <code>OutOfMemoryError</code>.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/76bb4bfbfeae827dce896f650655bbf6e251ed49">76bb4bfb</a>.</p> |
| |
| <p>This issue was reported to the Tomcat Security Team on 14 September 2023. |
| The issue was made public on 10 October 2023.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.13</p> |
| |
| <p><strong>Important: Information Disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42795" rel="nofollow">CVE-2023-42795</a></p> |
| |
| <p>When recycling various internal objects, including the request and the |
| response, prior to re-use by the next request/response, an error could |
| cause Tomcat to skip some parts of the recycling process leading to |
| information leaking from the current request/response to the next.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/9375d67106f8df9eb9d7b360b2bef052fe67d3d4">9375d671</a>.</p> |
| |
| <p>This issue was identified by the Tomcat Security Team on 13 September |
| 2023. The issue was made public on 10 October 2023.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.13</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.13"><span class="pull-right">2023-08-25</span> Fixed in Apache Tomcat 10.1.13</h3><div class="text"> |
| |
| <p><strong>Moderate: Open redirect</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41080" rel="nofollow">CVE-2023-41080</a></p> |
| |
| <p>If the ROOT (default) web application is configured to use FORM |
| authentication then it is possible that a specially crafted URL could be |
| used to trigger a redirect to an URL of the attackers choice.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/bb4624a9f3e69d495182ebfa68d7983076407a27">bb4624a9</a>.</p> |
| |
| <p>This issue was reported to the Tomcat Security Team on 17 August 2023. The |
| issue was made public on 22 August 2023.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.12</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.9"><span class="pull-right">2023-05-19</span> Fixed in Apache Tomcat 10.1.9</h3><div class="text"> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34981" rel="nofollow">CVE-2023-34981</a></p> |
| |
| <p>The fix for bug <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=66512">66512</a> introduced a regression that was fixed |
| as bug <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=66591">66591</a>. The regression meant that, if a response did not |
| have any HTTP headers set, no AJP <code>SEND_HEADERS</code> message would |
| be sent which in turn meant that at least one AJP based proxy |
| (mod_proxy_ajp) would use the response headers from the previous request |
| for the current request leading to an information leak.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/f0742f47b98aca943097f7f88e0d1163f57527e3">f0742f47</a>.</p> |
| |
| <p>This issue was reported to the Tomcat Security Team on 24 May 2023. The |
| issue was made public on 21 June 2023.</p> |
| |
| <p>Affects: 10.1.8</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.8"><span class="pull-right">2023-04-19</span> Fixed in Apache Tomcat 10.1.8</h3><div class="text"> |
| |
| <p><strong>Moderate: Apache Tomcat denial of service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28709" rel="nofollow">CVE-2023-28709</a></p> |
| |
| <p>The fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24998" rel="nofollow">CVE-2023-24998</a> was incomplete. If non-default HTTP |
| connector settings were used such that the <code>maxParameterCount</code> |
| could be reached using query string parameters and a request was |
| submitted that supplied exactly <code>maxParameterCount</code> parameters |
| in the query string, the limit for uploaded request parts could be |
| bypassed with the potential for a denial of service to occur.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/ba848da71c523d94950d3c53c19ea155189df9dc">ba848da7</a>.</p> |
| |
| <p>This issue was reported to the Tomcat Security Team on 13 March 2023. The |
| issue was made public on 22 May 2023.</p> |
| |
| <p>Affects: 10.1.5 to 10.1.7</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.6"><span class="pull-right">2023-02-24</span> Fixed in Apache Tomcat 10.1.6</h3><div class="text"> |
| |
| <p><strong>Important: Apache Tomcat information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28708" rel="nofollow">CVE-2023-28708</a></p> |
| |
| <p>When using the <code>RemoteIpFilter</code> with requests received from a |
| reverse proxy via HTTP that include the <code>X-Forwarded-Proto</code> |
| header set to <code>https</code>, session cookies created by Tomcat did not |
| include the secure attribute. This could result in the user agent |
| transmitting the session cookie over an insecure channel.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/f509bbf31fc00abe3d9f25ebfabca5e05173da5b">f509bbf3</a>.</p> |
| |
| <p><a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=66471">66471</a> was reported publicly on 8 February 2023. The security |
| implications were identified by the Tomcat Security team on 9 February |
| 2023. The issue was made public on 22 March 2023.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.5</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.5"><span class="pull-right">2023-01-13</span> Fixed in Apache Tomcat 10.1.5</h3><div class="text"> |
| |
| <p><strong>Important: Apache Tomcat denial of service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24998" rel="nofollow">CVE-2023-24998</a></p> |
| |
| <p>Apache Tomcat uses a packaged renamed copy of Apache Commons FileUpload |
| to provide the file upload functionality defined in the Jakarta Servlet |
| specification. Apache Tomcat was, therefore, also vulnerable to the |
| Apache Commons FileUpload vulnerability <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24998" rel="nofollow">CVE-2023-24998</a> as |
| there was no limit to the number of request parts processed. This |
| resulted in the possibility of an attacker triggering a DoS with a |
| malicious upload or series of uploads.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/8a2285f13affa961cc65595aad999db5efae45ce">8a2285f1</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team on 11 |
| December 2022. The issue was made public on 20 February 2023.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.4</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.2"><span class="pull-right">2022-11-14</span> Fixed in Apache Tomcat 10.1.2</h3><div class="text"> |
| |
| <p><strong>Low: Apache Tomcat JsonErrorReportValve injection</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45143" rel="nofollow">CVE-2022-45143</a></p> |
| |
| <p>The <code>JsonErrorReportValve</code> did not escape the |
| <code>type</code>, <code>message</code> or <code>description</code> |
| values. In some circumstances these are constructed from user provided |
| data and it was therefore possible for users to supply values that |
| invalidated or manipulated the JSON output.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/6a0ac6a438cbbb66b6e9c5223842f53bf0cb50aa">6a0ac6a4</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat Security team on 2 |
| September 2022. The issue was made public on 3 January 2023.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.1</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.1"><span class="pull-right">2022-10-11</span> Fixed in Apache Tomcat 10.1.1</h3><div class="text"> |
| |
| <p><strong>Low: Apache Tomcat request smuggling</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42252" rel="nofollow">CVE-2022-42252</a></p> |
| |
| <p>If Tomcat was configured to ignore invalid HTTP headers via setting |
| <code>rejectIllegalHeader</code> to <code>false</code> (not the default), |
| Tomcat did not reject a request containing an invalid |
| <code>Content-Length</code> header making a request smuggling attack |
| possible if Tomcat was located behind a reverse proxy that also failed to |
| reject the request with the invalid header.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/c9fe754e5d17e262dfbd3eab2a03ca96ff372dc3">c9fe754e</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team on 29 |
| September 2022. The issue was made public on 31 October 2022.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.0</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.27"><span class="pull-right">2022-10-10</span> Fixed in Apache Tomcat 10.0.27</h3><div class="text"> |
| |
| <p><strong>Low: Apache Tomcat request smuggling</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42252" rel="nofollow">CVE-2022-42252</a></p> |
| |
| <p>If Tomcat was configured to ignore invalid HTTP headers via setting |
| <code>rejectIllegalHeader</code> to <code>false</code> (not the default), |
| Tomcat did not reject a request containing an invalid |
| <code>Content-Length</code> header making a request smuggling attack |
| possible if Tomcat was located behind a reverse proxy that also failed to |
| reject the request with the invalid header.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/0d089a15047faf9cb3c82f80f4d28febd4798920">0d089a15</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team on 29 |
| September 2022. The issue was made public on 31 October 2022.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.26</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.23"><span class="pull-right">2022-07-26</span> Fixed in Apache Tomcat 10.0.23</h3><div class="text"> |
| |
| <p><strong>Low: Apache Tomcat XSS in examples web application</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-34305" rel="nofollow">CVE-2022-34305</a></p> |
| |
| <p>The Form authentication example in the examples web application displayed |
| user provided data without filtering, exposing a XSS vulnerability.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/1a7e95d9c3ef18c4efb5eb997fd1553a71dc6c80">1a7e95d9</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team on 22 June |
| 2022. The issue was made public on 23 June 2022.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.22</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.0-M17"><span class="pull-right">2022-07-20</span> Fixed in Apache Tomcat 10.1.0-M17</h3><div class="text"> |
| |
| <p><strong>Low: Apache Tomcat XSS in examples web application</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-34305" rel="nofollow">CVE-2022-34305</a></p> |
| |
| <p>The Form authentication example in the examples web application displayed |
| user provided data without filtering, exposing a XSS vulnerability.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/d6251d1cfb683f1bdd00ed022ac8e9b9a7e7792c">d6251d1c</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team on 22 June |
| 2022. The issue was made public on 23 June 2022.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.0-M16</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.21"><span class="pull-right">2022-05-06</span> Fixed in Apache Tomcat 10.0.21</h3><div class="text"> |
| |
| <p><strong>Low: Apache Tomcat EncryptInterceptor DoS</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29885" rel="nofollow">CVE-2022-29885</a></p> |
| |
| <p>The documentation for the EncryptInterceptor incorrectly stated it |
| enabled Tomcat clustering to run over an untrusted network. This was not |
| correct. While the EncryptInterceptor does provide confidentiality and |
| integrity protection, it does not protect against all risks associated |
| with running over any untrusted network, particularly DoS risks.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/36826ea638457d7e17876a70f89cb435b6db0d91">36826ea6</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team by 4ra1n on 17 |
| April 2022. The issue was made public on 10 May 2022.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.20</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.0-M15"><span class="pull-right">16 May 2022</span> Fixed in Apache Tomcat 10.1.0-M15</h3><div class="text"> |
| |
| <p><strong>Low: Apache Tomcat EncryptInterceptor DoS</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29885" rel="nofollow">CVE-2022-29885</a></p> |
| |
| <p>The documentation for the EncryptInterceptor incorrectly stated it |
| enabled Tomcat clustering to run over an untrusted network. This was not |
| correct. While the EncryptInterceptor does provide confidentiality and |
| integrity protection, it does not protect against all risks associated |
| with running over any untrusted network, particularly DoS risks.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/0fa7721f11d565a2cd2e44366c388ad6a3e6357d">0fa7721f</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team by 4ra1n on 17 |
| April 2022. The issue was made public on 10 May 2022.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.0-M14</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.20"><span class="pull-right">1 April 2022</span> Fixed in Apache Tomcat 10.0.20</h3><div class="text"> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 10.0.19 but the |
| release vote for the 10.0.19 release candidate did not pass. Therefore, |
| although users must download 10.0.20 to obtain a version that includes a |
| fix for these issues, version 10.0.19 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>High: Information Disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43980" rel="nofollow">CVE-2021-43980</a></p> |
| |
| <p>The simplified implementation of blocking reads and writes introduced in |
| Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long |
| standing (but extremely hard to trigger) concurrency bug that could cause |
| client connections to share an Http11Processor instance resulting in |
| responses, or part responses, to be received by the wrong client.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/17f177eeb7df5938f67ef9ea580411b120195f13">17f177ee</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team by Adam |
| Thomas, Richard Hernandez and Ryan Schmitt on 11 November 2021. The issue |
| was made public on 28 September 2022.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.18</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.0-M14"><span class="pull-right">1 April 2022</span> Fixed in Apache Tomcat 10.1.0-M14</h3><div class="text"> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 10.1.0-M13 but the |
| release vote for the 10.1.0-M13 release candidate did not pass. Therefore, |
| although users must download 10.1.0-M14 to obtain a version that includes a |
| fix for these issues, version 10.1.0-M13 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>High: Information Disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43980" rel="nofollow">CVE-2021-43980</a></p> |
| |
| <p>The simplified implementation of blocking reads and writes introduced in |
| Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long |
| standing (but extremely hard to trigger) concurrency bug that could cause |
| client connections to share an Http11Processor instance resulting in |
| responses, or part responses, to be received by the wrong client.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/9651b83a1d04583791525e5f0c4c9089f678d9fc">9651b83a</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team by Adam |
| Thomas, Richard Hernandez and Ryan Schmitt on 11 November 2021. The issue |
| was made public on 28 September 2022.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.0-M12</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.16"><span class="pull-right">20 January 2022</span> Fixed in Apache Tomcat 10.0.16</h3><div class="text"> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 10.0.15 but the |
| release vote for the 10.0.15 release candidate did not pass. Therefore, |
| although users must download 10.0.16 to obtain a version that includes a |
| fix for these issues, version 10.0.15 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Low: Local Privilege Escalation</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23181" rel="nofollow">CVE-2022-23181</a></p> |
| |
| <p>The fix for bug <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a> introduced a time of check, time |
| of use vulnerability that allowed a local attacker to perform actions |
| with the privileges of the user that the Tomcat process is using. This |
| issue is only exploitable when Tomcat is configured to persist sessions |
| using the FileStore.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/094800b12d6c958d7b4540372c5a95698658ada1">094800b1</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team by Trung Pham |
| of Viettel Cyber Security on 10 December 2021. The issue was made public |
| on 26 January 2022.</p> |
| |
| <p>Affects: 10.0.0-M5 to 10.0.14</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.0-M10"><span class="pull-right">20 January 2022</span> Fixed in Apache Tomcat 10.1.0-M10</h3><div class="text"> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 10.1.0-M9 but the |
| release vote for the 10.1.0-M9 release candidate did not pass. Therefore, |
| although users must download 10.1.0-M10 to obtain a version that includes a |
| fix for these issues, version 10.1.0-M9 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Low: Local Privilege Escalation</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23181" rel="nofollow">CVE-2022-23181</a></p> |
| |
| <p>The fix for bug <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a> introduced a time of check, time |
| of use vulnerability that allowed a local attacker to perform actions |
| with the privileges of the user that the Tomcat process is using. This |
| issue is only exploitable when Tomcat is configured to persist sessions |
| using the FileStore.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/70da1aaa51e0f9d088438e9d958812a144e12754">70da1aaa</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team by Trung Pham |
| of Viettel Cyber Security on 10 December 2021. The issue was made public |
| on 26 January 2022.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.0-M8</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.12"><span class="pull-right">1 October 2021</span> Fixed in Apache Tomcat 10.0.12</h3><div class="text"> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42340" rel="nofollow">CVE-2021-42340</a></p> |
| |
| <p>The fix for bug <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=63362">63362</a> introduced a memory leak. The object |
| introduced to collect metrics for HTTP upgrade connections was not |
| released for WebSocket connections once the WebSocket connection was |
| closed. This created a memory leak that, over time, could lead to a |
| denial of service via an OutOfMemoryError.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/31d62426645824bdfe076a0c0eafa904d90b4fb9">31d62426</a>.</p> |
| |
| <p>The memory leak was reported publicly via the users mailing list on 23 |
| September 2021. The security implications were identified by the Tomcat |
| Security team the same day. The issue was made public on 14 October |
| 2021.</p> |
| |
| <p>Affects: 10.0.0-M10 to 10.0.11</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.1.0-M6"><span class="pull-right">1 October 2021</span> Fixed in Apache Tomcat 10.1.0-M6</h3><div class="text"> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42340" rel="nofollow">CVE-2021-42340</a></p> |
| |
| <p>The fix for bug <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=63362">63362</a> introduced a memory leak. The object |
| introduced to collect metrics for HTTP upgrade connections was not |
| released for WebSocket connections once the WebSocket connection was |
| closed. This created a memory leak that, over time, could lead to a |
| denial of service via an OutOfMemoryError.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/d5a6660cba7f51589468937bf3bbad4db7810371">d5a6660c</a>.</p> |
| |
| <p>The memory leak was reported publicly via the users mailing list on 23 |
| September 2021. The security implications were identified by the Tomcat |
| Security team the same day. The issue was made public on 14 October |
| 2021.</p> |
| |
| <p>Affects: 10.1.0-M1 to 10.1.0-M5</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.7"><span class="pull-right">15 June 2021</span> Fixed in Apache Tomcat 10.0.7</h3><div class="text"> |
| |
| <p><strong>Important: Request Smuggling</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33037" rel="nofollow">CVE-2021-33037</a></p> |
| |
| <p>Apache Tomcat did not correctly parse the HTTP transfer-encoding request |
| header in some circumstances leading to the possibility of request |
| smuggling when used with a reverse proxy. Specifically: Tomcat |
| incorrectly ignored the transfer-encoding header if the client declared |
| it would only accept an HTTP/1.0 response; Tomcat honoured the identify |
| encoding; and Tomcat did not ensure that, if present, the chunked |
| encoding was the final encoding.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/eee0d024c1b3171560c92eaba79dd6eb8eb11bcd">eee0d024</a>, |
| <a href="https://github.com/apache/tomcat/commit/506134f957a4be2c5b4a9334f7b3435fc954dbc1">506134f9</a> and |
| <a href="https://github.com/apache/tomcat/commit/19d11556d0db99df291df33605f137976d152475">19d11556</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team by Bahruz |
| Jabiyev, Steven Sprecher and Kaan Onarlioglu of NEU seclab on 7 May 2021. |
| The issue was made public on 12 July 2021.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.6</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.6"><span class="pull-right">12 May 2021</span> Fixed in Apache Tomcat 10.0.6</h3><div class="text"> |
| |
| <p><strong>Low: Authentication weakness</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30640" rel="nofollow">CVE-2021-30640</a></p> |
| |
| <p>Queries made by the JNDI Realm did not always correctly escape |
| parameters. Parameter values could be sourced from user provided data (eg |
| user names) as well as configuration data provided by an administrator. |
| In limited circumstances it was possible for users to authenticate using |
| variations of their user name and/or to bypass some of the protection |
| provided by the LockOut Realm.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/f4d9bdef53ec009b7717620d890465fa273721a6">f4d9bdef</a>, |
| <a href="https://github.com/apache/tomcat/commit/4e61e1d625a4a64d6b775e3a03c77a0b100d56d7">4e61e1d6</a>, |
| <a href="https://github.com/apache/tomcat/commit/d5303a506c7533803d2b3bc46e6120ce673a6667">d5303a50</a>, |
| <a href="https://github.com/apache/tomcat/commit/b930d0b3161d9ec78d5fa57f886ed2de4680518b">b930d0b3</a>, |
| <a href="https://github.com/apache/tomcat/commit/17208c645d68d2af1444ee8c64f36a9b8f0ba76f">17208c64</a>, |
| <a href="https://github.com/apache/tomcat/commit/bd4d1fbe9146dff4714130594afd668406a6a5ef">bd4d1fbe</a>, |
| <a href="https://github.com/apache/tomcat/commit/81f16b0a7186ed02efbfac336589d6cff28d1e89">81f16b0a</a> and |
| <a href="https://github.com/apache/tomcat/commit/eeb7351219bd8803c0053e1e80444664a7cf5b51">eeb73512</a>.</p> |
| |
| <p>This issue was reported publicly as <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=65224">65224</a>.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.5</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.5"><span class="pull-right">6 April 2021</span> Fixed in Apache Tomcat 10.0.5</h3><div class="text"> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30639" rel="nofollow">CVE-2021-30639</a></p> |
| |
| <p>An error introduced as part of a change to improve error handling during |
| non-blocking I/O meant that the error flag associated with the Request |
| object was not reset between requests. This meant that once a |
| non-blocking I/O error occurred, all future requests handled by that |
| request object would fail. Users were able to trigger non-blocking I/O |
| errors, e.g. by dropping a connection, thereby creating the possibility |
| of triggering a DoS.</p> |
| <o>Applications that do not use non-blocking I/O are not exposed to this |
| vulnerability.</o> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/b59099e4ca501a039510334ebe1024971cd6f959">b59099e4</a>.</p> |
| |
| <p>This issue was reported publicly as <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=65203">65203</a>.</p> |
| |
| <p>Affects: 10.0.3 to 10.0.4</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.4"><span class="pull-right">10 March 2021</span> Fixed in Apache Tomcat 10.0.4</h3><div class="text"> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 10.0.3 but the |
| release vote for the 10.0.3 release candidate did not pass. Therefore, |
| although users must download 10.0.4 to obtain a version that includes a |
| fix for these issues, version 10.0.3 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41079" rel="nofollow">CVE-2021-41079</a></p> |
| |
| <p>When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a |
| specially crafted packet could be used to trigger an infinite loop |
| resulting in a denial of service.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/34115fb3c83f6cd97772232316a492a4cc5729e0">34115fb3</a>.</p> |
| |
| <p>This issue was first reported to the Apache Tomcat Security Team by |
| Thomas Wozenilek on 26 February 2021 but could not be confirmed. A |
| speculative fix was applied on 3 March 2021. On 14 September 2021 David |
| Frankson of Infinite Campus independently reported the issue and included |
| a test case. This allowed both the issue and the speculative fix to be |
| verified. The issue was made public on 15 September 2021.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.2</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.2"><span class="pull-right">2 February 2021</span> Fixed in Apache Tomcat 10.0.2</h3><div class="text"> |
| |
| <p><i>Note: The issues below were fixed in Apache Tomcat 10.0.1 but the |
| release vote for the 10.0.1 release candidate did not pass. Therefore, |
| although users must download 10.0.2 to obtain a version that includes a |
| fix for these issues, version 10.0.1 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Low: Fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a> was incomplete</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25329" rel="nofollow">CVE-2021-25329</a></p> |
| |
| <p>The fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a> was incomplete. When using a |
| highly unlikely configuration edge case, the Tomcat instance was still |
| vulnerable to <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a>. Note that both the previously |
| published prerequisites for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a> and the previously |
| published non-upgrade mitigations for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a> also apply to |
| this issue.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/6d66e99ef85da93e4d2c2a536ca51aa3418bfaf4">6d66e99e</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team by Trung Pham |
| of Viettel Cyber Security on 12 January 2021. The issue was made public |
| on 1 March 2021.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.0</p> |
| |
| <p><strong>Important: Request mix-up with h2c</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25122" rel="nofollow">CVE-2021-25122</a></p> |
| |
| <p>When responding to new h2c connection requests, Apache Tomcat could |
| duplicate request headers and a limited amount of request body from one |
| request to another meaning user A and user B could both see the results of |
| user A's request.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/dd757c0a893e2e35f8bc1385d6967221ae8b9b9b">dd757c0a</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat Security team on 11 |
| January 2021. The issue was made public on 1 March 2021.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.0</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.0-M10"><span class="pull-right">17 November 2020</span> Fixed in Apache Tomcat 10.0.0-M10</h3><div class="text"> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24122" rel="nofollow">CVE-2021-24122</a></p> |
| |
| <p>When serving resources from a network location using the NTFS file system |
| it was possible to bypass security constraints and/or view the source |
| code for JSPs in some configurations. The root cause was the unexpected |
| behaviour of the JRE API <code>File.getCanonicalPath()</code> which in |
| turn was caused by the inconsistent behaviour of the Windows API |
| (<code>FindFirstFileW</code>) in some circumstances. |
| </p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/7f004ac4531c45f9a2a2d1470561fe135cf27bc2">7f004ac4</a>.</p> |
| |
| <p>This issue was reported the Apache Tomcat Security team by Ilja Brander |
| on 26 October 2020. The issue was made public on 14 January 2021.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.0-M9</p> |
| |
| <p><strong>Moderate: HTTP/2 request header mix-up</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17527" rel="nofollow">CVE-2020-17527</a></p> |
| |
| <p>While investigating issue <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=64830">64830</a> it was discovered that Apache |
| Tomcat could re-use an HTTP request header value from the previous stream |
| received on an HTTP/2 connection for the request associated with the |
| subsequent stream. While this would most likely lead to an error and the |
| closure of the HTTP/2 connection, it is possible that information could |
| leak between requests. |
| </p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/8d2fe6894d6e258a6d615d7f786acca80e6020cb">8d2fe689</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat Security team on 10 |
| November 2020. The issue was made public on 3 December 2020.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.0-M9</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.0-M8"><span class="pull-right">14 September 2020</span> Fixed in Apache Tomcat 10.0.0-M8</h3><div class="text"> |
| |
| <p><strong>Moderate: HTTP/2 request mix-up</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13943" rel="nofollow">CVE-2020-13943</a></p> |
| |
| <p>If an HTTP/2 client exceeded the agreed maximum number of concurrent |
| streams for a connection (in violation of the HTTP/2 protocol), it was |
| possible that a subsequent request made on that connection could contain |
| HTTP headers - including HTTP/2 pseudo headers - from a previous request |
| rather than the intended headers. This could lead to users seeing |
| responses for unexpected resources.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/1bbc650cbc3f08d85a1ec6d803c47ae53a84f3bb">1bbc650c</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat Security team on 23 July |
| 2020. The issue was made public on 12 October 2020.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.0-M7</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.0-M7"><span class="pull-right">5 July 2020</span> Fixed in Apache Tomcat 10.0.0-M7</h3><div class="text"> |
| |
| <p><strong>Important: WebSocket DoS</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13935" rel="nofollow">CVE-2020-13935</a></p> |
| |
| <p>The payload length in a WebSocket frame was not correctly validated. |
| Invalid payload lengths could trigger an infinite loop. Multiple requests |
| with invalid payload lengths could lead to a denial of service.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/1c1c77b0efb667cea80b532440b44cea1dc427c3">1c1c77b0</a>.</p> |
| |
| <p>This issue was reported publicly via the Apache Bugzilla instance on 28 |
| June 2020 and included references to high CPU but no specific reference |
| to denial of service. The associated DoS risks were identified by the |
| Apache Tomcat Security Team the same day. The issue was made public on 14 |
| July 2020.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.0-M6</p> |
| |
| <p><strong>Moderate: HTTP/2 DoS</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13934" rel="nofollow">CVE-2020-13934</a></p> |
| |
| <p>An h2c direct connection did not release the HTTP/1.1 processor after the |
| upgrade to HTTP/2. If a sufficient number of such requests were made, an |
| OutOfMemoryException could occur leading to a denial of service.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/c9167ae30f3b03b112f3d81772e3450b7d0e6a25">c9167ae3</a>.</p> |
| |
| <p>This issue was reported publicly via the Apache Tomcat Users mailing list |
| on 22 June 2020 without reference to the potential for DoS. After further |
| discussion to identify the steps necessary to reproduce the issue, the |
| root cause of the issue and the associated DoS risks were identified by |
| the Apache Tomcat Security Team on 26 June 2020. The issue was made |
| public on 14 July 2020.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.0-M6</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.0-M6"><span class="pull-right">7 June 2020</span> Fixed in Apache Tomcat 10.0.0-M6</h3><div class="text"> |
| |
| <p><strong>Important: HTTP/2 DoS</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11996" rel="nofollow">CVE-2020-11996</a></p> |
| |
| <p>A specially crafted sequence of HTTP/2 requests could trigger high CPU |
| usage for several seconds. If a sufficient number of such requests were |
| made on concurrent HTTP/2 connections, the server could become |
| unresponsive.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/9434a44d3449d620b1be70206819f8275b4a7509">9434a44d</a>.</p> |
| |
| <p>This issue was reported publicly via the Apache Tomcat Users mailing list |
| on 21 May 2020 without reference to the potential for DoS. The DoS risks |
| were identified by the Apache Tomcat Security Team the same day. The |
| issue was made public on 25 June 2020.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.0-M5</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_10.0.0-M5"><span class="pull-right">11 May 2020</span> Fixed in Apache Tomcat 10.0.0-M5</h3><div class="text"> |
| |
| <p><strong>Important: Remote Code Execution via session persistence</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a></p> |
| |
| <p>If:</p> |
| <ul> |
| <li>an attacker is able to control the contents and name of a file on the |
| server; and</li> |
| <li>the server is configured to use the <code>PersistenceManager</code> |
| with a <code>FileStore</code>; and</li> |
| <li>the <code>PersistenceManager</code> is configured with |
| <code>sessionAttributeValueClassNameFilter="null"</code> (the default |
| unless a <code>SecurityManager</code> is used) or a sufficiently lax |
| filter to allow the attacker provided object to be deserialized; |
| and</li> |
| <li>the attacker knows the relative file path from the storage location |
| used by <code>FileStore</code> to the file the attacker has control |
| over;</li> |
| </ul> |
| <p>then, using a specifically crafted request, the attacker will be able to |
| trigger remote code execution via deserialization of the file under their |
| control.</p> |
| |
| <p><strong>Note:</strong> All of conditions above must be true for the |
| attack to succeed.</p> |
| |
| <p>As an alternative to upgrading to 10.0.0-M5 or later, users may configure |
| the <code>PersistenceManager</code> with an appropriate value for |
| <code>sessionAttributeValueClassNameFilter</code> to ensure that only |
| application provided attributes are serialized and deserialized.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/bb33048e3f9b4f2b70e4da2e6c4e34ca89023b1b">bb33048e</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security Team by jarvis |
| threedr3am of pdd security research on 12 April 2020. The issue was made |
| public on 20 May 2020.</p> |
| |
| <p>Affects: 10.0.0-M1 to 10.0.0-M4</p> |
| |
| </div><h3 id="Not_a_vulnerability_in_Tomcat">Not a vulnerability in Tomcat</h3><div class="text"> |
| |
| <p><strong>Critical: Remote Code Execution via log4j</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228" rel="nofollow">CVE-2021-44228</a></p> |
| |
| <p>Apache Tomcat 10.x has no dependency on any version of log4j.</p> |
| |
| <p>Web applications deployed on Apache Tomcat may have a dependency on |
| log4j. You should seek support from the application vendor in this |
| instance.</p> |
| |
| <p>It is possible to configure Apache Tomcat 10.x to use log4j 2.x for |
| Tomcat's internal logging. This requires explicit configuration and the |
| addition of the log4j 2.x library. Anyone who has switched Tomcat's |
| internal logging to log4j 2.x is likely to need to address this |
| vulnerability.</p> |
| |
| <p>In most cases, disabling the problematic feature will be the simplest |
| solution. Exactly how to do that depends on the exact version of log4j |
| 2.x being used. Details are provided on the |
| <a href="https://logging.apache.org/log4j/2.x/security.html">log4j 2.x |
| security page</a>.</p> |
| |
| </div></div></div></div></main><footer id="footer"> |
| Copyright © 1999-2026, The Apache Software Foundation |
| <br> |
| Apache Tomcat, Tomcat, Apache, the Apache Tomcat logo and the Apache logo |
| are either registered trademarks or trademarks of the Apache Software |
| Foundation. |
| </footer></div><script src="res/js/tomcat.js"></script></body></html> |