| <!DOCTYPE html SYSTEM "about:legacy-compat"> |
| <html lang="en"><head><META http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" type="text/css"><title>Apache Tomcat® - Reporting Security Problems</title><meta name="author" content="Apache Tomcat Project"><script src="https://www.apachecon.com/event-images/snippet.js"></script></head><body><div id="wrapper"><header id="header"><div class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div class="hamburger"></div></div><a href="http://tomcat.apache.org/"><img class="tomcat-logo pull-left noPrint" alt="Tomcat Home" src="res/images/tomcat.png"></a><h1 class="pull-left">Apache Tomcat<sup>®</sup></h1><div class="asf-logos pull-right"><a href="https://www.apache.org/foundation/contributing.html" target="_blank" class="pull-left"><img src="https://www.apache.org/images/SupportApache-small.png" class="support-asf" alt="Support Apache"></a><a href="http://www.apache.org/" target="_blank" class="pull-left"><img src="res/images/asf_logo_wide.svg" class="asf-logo" alt="The Apache Software Foundation"></a></div></div></header><main id="middle"><div><div id="mainLeft"><div id="nav-wrapper"><form action="https://www.google.com/search" method="get"><div class="searchbox"><input value="tomcat.apache.org" name="sitesearch" type="hidden"><input aria-label="Search text" placeholder="Search…" required="required" name="q" id="query" type="search"><button>GO</button></div></form><div class="asfevents"><a class="acevent" data-format="square" data-width="150"></a></div><nav><div><h2>Apache Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a href="./whichversion.html">Which version?</a></li><li><a href="https://tomcat.apache.org/download-11.cgi">Tomcat 11</a></li><li><a href="https://tomcat.apache.org/download-10.cgi">Tomcat 10</a></li><li><a href="https://tomcat.apache.org/download-90.cgi">Tomcat 9</a></li><li><a href="https://tomcat.apache.org/download-migration.cgi">Tomcat Migration Tool for Jakarta EE</a></li><li><a href="https://tomcat.apache.org/download-connectors.cgi">Tomcat Connectors</a></li><li><a href="https://tomcat.apache.org/download-native.cgi">Tomcat Native</a></li><li><a href="https://tomcat.apache.org/download-taglibs.cgi">Taglibs</a></li><li><a href="https://archive.apache.org/dist/tomcat/">Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a href="./tomcat-11.0-doc/index.html">Tomcat 11.0</a></li><li><a href="./tomcat-10.1-doc/index.html">Tomcat 10.1</a></li><li><a href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a href="./upgrading.html">Upgrading</a></li><li><a href="./connectors-doc/index.html">Tomcat Connectors</a></li><li><a href="./native-doc/index.html">Tomcat Native 2</a></li><li><a href="./native-1.3-doc/index.html">Tomcat Native 1.3</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT">Wiki</a></li><li><a href="./migration.html">Migration Guide</a></li><li><a href="./presentations.html">Presentations</a></li><li><a href="https://cwiki.apache.org/confluence/x/Bi8lBg">Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a href="./security.html">Security Reports</a></li><li><a href="./findhelp.html">Find help</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ">FAQ</a></li><li><a href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug Database</a></li></ul></div><div><h2>Get Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a href="./source.html">Source code</a></li><li><a href="./ci.html">Buildbot</a></li><li><a href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a href="https://www.youtube.com/c/ApacheTomcatOfficial">YouTube</a></li></ul></div><div><h2>Misc</h2><ul><li><a href="./whoweare.html">Who We Are</a></li><li><a href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat">Swag</a></li><li><a href="./heritage.html">Heritage</a></li><li><a href="http://www.apache.org">Apache Home</a></li><li><a href="./resources.html">Resources</a></li><li><a href="./contact.html">Contact</a></li><li><a href="./legal.html">Legal</a></li><li><a href="https://privacy.apache.org/policies/privacy-policy-public.html">Privacy</a></li><li><a href="https://www.apache.org/foundation/contributing.html">Support Apache</a></li><li><a href="https://www.apache.org/foundation/sponsorship.html">Sponsorship</a></li><li><a href="http://www.apache.org/foundation/thanks.html">Thanks</a></li><li><a href="http://www.apache.org/licenses/">License</a></li></ul></div></nav></div></div><div id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 id="Security_Updates">Security Updates</h3><div class="text"> |
| |
| <p>Please note that, except in rare circumstances, binary patches are not |
| produced for individual vulnerabilities. To obtain the binary fix for a |
| particular vulnerability you should upgrade to an Apache |
| Tomcat<sup>®</sup> version where that vulnerability has been |
| fixed.</p> |
| |
| <p>Source patches, usually in the form of references to commits, may be |
| provided in either in a vulnerability announcement and/or the |
| vulnerability details listed on these pages. These source patches may be |
| used by users wishing to build their own local version of Tomcat with just |
| that security patch rather than upgrade.</p> |
| |
| <p>Lists of security problems fixed in currently supported versions of |
| Apache Tomcat are available:</p> |
| <ul> |
| <li><a href="security-11.html">Apache Tomcat 11.x Security Vulnerabilities |
| </a></li> |
| <li><a href="security-10.html">Apache Tomcat 10.x Security Vulnerabilities |
| </a></li> |
| <li><a href="security-9.html">Apache Tomcat 9.x Security Vulnerabilities |
| </a></li> |
| <li><a href="security-jk.html">Apache Tomcat JK Connectors Security |
| Vulnerabilities</a></li> |
| <li><a href="security-native.html">Apache Tomcat APR/native Connector |
| Security Vulnerabilities</a></li> |
| <li><a href="security-taglibs.html">Apache Taglibs |
| Security Vulnerabilities</a></li> |
| </ul> |
| |
| <p>Lists of security problems fixed in versions of Apache Tomcat that have |
| reached end of life and may be downloaded from the archives are also |
| available:</p> |
| <ul> |
| <li><a href="security-8.html">Apache Tomcat 8.x Security Vulnerabilities |
| </a></li> |
| <li><a href="security-7.html">Apache Tomcat 7.x Security Vulnerabilities |
| </a></li> |
| <li><a href="security-6.html">Apache Tomcat 6.x Security Vulnerabilities |
| </a></li> |
| <li><a href="security-5.html">Apache Tomcat 5.x Security Vulnerabilities |
| </a></li> |
| <li><a href="security-4.html">Apache Tomcat 4.x Security Vulnerabilities |
| </a></li> |
| <li><a href="security-3.html">Apache Tomcat 3.x Security Vulnerabilities |
| </a></li> |
| </ul> |
| |
| </div><h3 id="Reporting_New_Security_Problems_with_Tomcat">Reporting New Security Problems with Tomcat</h3><div class="text"> |
| <p>The ASF takes a very active stance in eliminating security problems and |
| denial of service attacks against Tomcat. |
| </p> |
| |
| <p>We strongly encourage folks to report such problems to our private |
| security mailing list first, before disclosing them in a public forum. |
| </p> |
| |
| <p><strong>Please note that the security mailing list should only be used |
| for reporting undisclosed security vulnerabilities in Tomcat and managing |
| the process of fixing such vulnerabilities. We cannot accept regular bug |
| reports, provide free consulting or answer other queries at this address. |
| All mail sent to this address that does not relate to an undisclosed |
| security problem in the Tomcat source code will be ignored.</strong> |
| The private security mailing address is: |
| <a href="mailto:security@tomcat.apache.org"> |
| security<span>@</span>tomcat.apache.org</a></p> |
| |
| <p>The Tomcat <a href="security-model.html">security model</a> describes |
| what the Tomcat security team will and will not accept as a valid |
| vulnerability report for Tomcat.</p> |
| |
| <p>Note that all networked servers are subject to denial of service attacks, |
| and we cannot promise magic workarounds to generic problems (such as a |
| client streaming lots of data to your server, or re-requesting the same |
| URL repeatedly). In general our philosophy is to avoid any attacks which |
| can cause the server to consume resources in a non-linear relationship to |
| the size of inputs.</p> |
| |
| <p>Questions about:</p> |
| <ul> |
| <li>how to configure Tomcat securely</li> |
| <li>if a vulnerability applies to your particular application</li> |
| <li>obtaining further information on a published vulnerability</li> |
| <li>availability of patches and/or new releases</li> |
| </ul> |
| <p>should be addressed to the users mailing list. Please see the |
| <a href="lists.html">mailing lists</a> page for details of how to |
| subscribe.</p> |
| |
| <p>If you need to report a bug that isn't an undisclosed security |
| vulnerability, please use the <a href="bugreport.html">bug reporting |
| page</a>.</p> |
| |
| <p>If you are interested in how reported vulnerabilities are handled, the |
| process is documented at ASF-wide pages |
| <a href="https://apache.org/security/#vulnerability-handling">[1]</a> and |
| <a href="https://apache.org/security/committers.html#possible">[2]</a>. |
| </p> |
| </div><h3 id="Errors_and_omissions">Errors and omissions</h3><div class="text"> |
| |
| <p>Please report any errors or omissions to |
| <a href="mailto:security@tomcat.apache.org">security@tomcat.apache.org |
| </a>. |
| </p> |
| |
| </div></div></div></div></main><footer id="footer"> |
| Copyright © 1999-2026, The Apache Software Foundation |
| <br> |
| Apache Tomcat, Tomcat, Apache, the Apache Tomcat logo and the Apache logo |
| are either registered trademarks or trademarks of the Apache Software |
| Foundation. |
| </footer></div><script src="res/js/tomcat.js"></script></body></html> |