Dependency scanning
Check whether org.apache.tomcat.embed:tomcat-embed-core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-38286
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
CVE-2025-55668
Apache Tomcat Session Fixation vulnerability
CVE-2025-52434
Apache Tomcat is vulnerable to resource exhaustion when using the APR/Native connector
CVE-2024-21733
Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2023-24998
Apache Commons FileUpload denial of service vulnerability
CVE-2019-0221
Cross-site scripting in Apache Tomcat
CVE-2023-45648
Apache Tomcat Improper Input Validation vulnerability
CVE-2023-42795
Apache Tomcat Incomplete Cleanup vulnerability
CVE-2025-66614
Apache Tomcat - Client certificate verification bypass
CVE-2020-11996
Uncontrolled Resource Consumption in Apache Tomcat
CVE-2023-41080
Apache Tomcat Open Redirect vulnerability
CVE-2021-25122
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
CVE-2026-43515
Apache Tomcat - Security constraints not correctly applied
CVE-2026-43514
Apache Tomcat - AJP secret compared in non-constant time
CVE-2026-29129
Apache Tomcat: Configured cipher preference order not preserved
CVE-2026-24880
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
CVE-2020-9484
Potential remote code execution in Apache Tomcat
CVE-2019-0199
Apache Tomcat Denial of Service vulnerability
CVE-2023-44487
HTTP/2 Stream Cancellation Attack
CVE-2026-41293
Apache Tomcat - HTTP/2 request headers not validated
CVE-2026-42498
Apache Tomcat - WebSocket authentication header exposure
CVE-2026-43512
Apache Tomcat - Digest authenticator will authenticate any unknown user
CVE-2026-43513
Apache Tomcat: LockOutRealm treats user names as case-sensitive
CVE-2026-41284
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
CVE-2020-1935
Potential HTTP request smuggling in Apache Tomcat
CVE-2020-1938
Improper Privilege Management in Tomcat
CVE-2025-55752
Apache Tomcat Vulnerable to Relative Path Traversal
CVE-2025-48989
Apache Tomcat Improper Resource Shutdown or Release vulnerability
CVE-2025-55754
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
CVE-2025-61795
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
CVE-2026-34483
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
CVE-2026-25854
Apache Tomcat has an Open Redirect vulnerability
CVE-2026-32990
Apache Tomcat has an Improper Input Validation vulnerability
CVE-2023-28709
Apache Tomcat - Fix for CVE-2023-24998 was incomplete
CVE-2026-24734
Apache Tomcat has an Improper Input Validation vulnerability
CVE-2025-52520
Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits
CVE-2025-53506
Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams
CVE-2021-25329
Potential remote code execution in Apache Tomcat
CVE-2019-12418
Insufficiently Protected Credentials in Apache Tomcat
CVE-2025-46701
Apache Tomcat - CGI security constraint bypass
CVE-2023-46589
Apache Tomcat Improper Input Validation vulnerability
CVE-2019-17563
In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
CVE-2025-49125
Apache Tomcat - Security constraint bypass for pre/post-resources
CVE-2025-31651
Apache Tomcat Rewrite rule bypass
CVE-2024-50379
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
CVE-2024-24549
Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
CVE-2024-56337
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
CVE-2025-48988
Apache Tomcat - DoS in multipart upload
CVE-2025-31650
Apache Tomcat Denial of Service via invalid HTTP priority header
CVE-2021-24122
Information Disclosure in Apache Tomcat
CVE-2024-34750
Apache Tomcat - Denial of Service
CVE-2025-49124
Apache Tomcat installer for Windows has an untrusted search path vulnerability
CVE-2017-12615
When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the server
CVE-2017-12617
Unrestricted Upload of File with Dangerous Type Apache Tomcat
CVE-2008-1947
Apache Tomcat Cross-site scripting (XSS) vulnerability
CVE-2024-52317
Apache Tomcat Request and/or response mix-up
GHSA-r53m-pfr5-7v87
Moderate severity vulnerability that affects org.apache.tomcat.embed:tomcat-embed-core
CVE-2018-1305
Apache Tomcat information exposure vulnerability
CVE-2018-1304
Apache Tomcat unauthorized access vulnerability
CVE-2014-0095
Denial of service in Apache Tomcat
CVE-2018-8034
The host name verification missing in Apache Tomcat
CVE-2023-34981
Apache Tomcat vulnerable to information leak
CVE-2022-45143
Apache Tomcat improperly escapes input from JsonErrorReportValve
CVE-2022-42252
Apache Tomcat may reject request containing invalid Content-Length header
CVE-2017-5651
Expected Behavior Violation in Apache Tomcat
CVE-2017-5648
Exposure of Resource to Wrong Sphere in Apache Tomcat
CVE-2019-0232
Apache Tomcat OS Command Injection vulnerability
CVE-2018-1336
In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder
CVE-2018-8014
The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for all origins
CVE-2019-10072
Improper Locking in Apache Tomcat
CVE-2018-8037
Apache Tomcat Race Condition vulnerability
CVE-2018-11784
Apache Tomcat Open Redirect vulnerability
CVE-2019-17569
Potential HTTP request smuggling in Apache Tomcat
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes