Dependency scanning
Check whether org.apache.tomcat:tomcat is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-54677
Apache Tomcat Uncontrolled Resource Consumption vulnerability
CVE-2026-34487
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
CVE-2024-52318
Apache Tomcat - XSS in generated JSPs
CVE-2019-0221
Cross-site scripting in Apache Tomcat
CVE-2023-45648
Apache Tomcat Improper Input Validation vulnerability
CVE-2023-42795
Apache Tomcat Incomplete Cleanup vulnerability
CVE-2025-66614
Apache Tomcat - Client certificate verification bypass
CVE-2020-13935
Infinite Loop in Apache Tomcat
CVE-2020-11996
Uncontrolled Resource Consumption in Apache Tomcat
CVE-2009-3555
Apache Tomcat affected by vulnerability in TLS and SSL protocol
CVE-2026-34486
Apache Tomcat Missing Encryption of Sensitive Data vulnerability
CVE-2023-41080
Apache Tomcat Open Redirect vulnerability
CVE-2026-43515
Apache Tomcat - Security constraints not correctly applied
CVE-2026-43514
Apache Tomcat - AJP secret compared in non-constant time
CVE-2026-29129
Apache Tomcat: Configured cipher preference order not preserved
CVE-2026-29145
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
CVE-2020-13934
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
CVE-2026-41293
Apache Tomcat - HTTP/2 request headers not validated
CVE-2026-42498
Apache Tomcat - WebSocket authentication header exposure
CVE-2026-43512
Apache Tomcat - Digest authenticator will authenticate any unknown user
CVE-2026-43513
Apache Tomcat: LockOutRealm treats user names as case-sensitive
CVE-2026-41284
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
CVE-2020-1935
Potential HTTP request smuggling in Apache Tomcat
CVE-2022-25762
Improper socket reuse in Apache Tomcat
CVE-2025-55752
Apache Tomcat Vulnerable to Relative Path Traversal
CVE-2025-55754
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
CVE-2025-61795
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
CVE-2026-34483
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
CVE-2026-29146
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
CVE-2026-25854
Apache Tomcat has an Open Redirect vulnerability
CVE-2026-32990
Apache Tomcat has an Improper Input Validation vulnerability
CVE-2020-8022
Incorrect Default Permissions in Apache Tomcat
CVE-2007-0450
Apache Tomcat Directory Traversal
CVE-2025-49124
Apache Tomcat installer for Windows has an untrusted search path vulnerability
CVE-2015-5345
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
CVE-2015-5174
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
CVE-2014-0099
Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Tomcat
CVE-2014-0119
Missing XML Validation in Apache Tomcat
CVE-2014-0096
Improper Input Validation in Apache Tomcat
CVE-2014-0075
Integer Overflow or Wraparound in Apache Tomcat
CVE-2012-3544
Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions
CVE-2009-0783
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
CVE-2008-1947
Apache Tomcat Cross-site scripting (XSS) vulnerability
CVE-2007-3385
Apache Tomcat Mishandles Character Sequence in Cookies
CVE-2007-5333
Exposure of Sensitive Information in Apache Tomcat
CVE-2006-7196
Cross-site scripting in Apache Tomcat
CVE-2006-7197
Apache Tomcat Buffer Over-Read
CVE-2006-3835
Apache Tomcat Reveals Directories
CVE-2002-2009
Apache Tomcat Leaks Pathname Information via Error Message
CVE-2002-2008
Apache Tomcat Leaks Information via Error Message
CVE-2003-0043
Tomcat uses trusted privileges when processing web.xml file
CVE-2001-0917
Apache Tomcat Reveals Path through Long URL
CVE-2005-3510
Apache Tomcat Vulnerable to Denial of Service (DoS) via Simultaneous Requests
CVE-2014-0227
Improper Input Validation in Apache Tomcat
CVE-2014-0230
Uncontrolled Resource Consumption in Apache Tomcat
CVE-2013-4286
Apache Tomcat is vulnerable to HTTP request-smuggling
CVE-2013-2071
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
CVE-2014-7810
Improper Access Control in Apache Tomcat
CVE-2013-2185
Deserialization of Untrusted Data in Apache Tomcat
CVE-2014-0050
Commons FileUpload Denial of service vulnerability
CVE-2013-4444
Apache Tomcat Unrestricted file upload vulnerability
CVE-2013-4322
Apache Tomcat Denial of Service vulnerability
CVE-2013-4590
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
CVE-2016-6794
System Property Disclosure in Apache Tomcat
CVE-2016-6796
Apache Tomcat vulnerable to SecurityManager bypass
CVE-2016-8747
Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request
CVE-2016-6817
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
CVE-2017-5647
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
CVE-2016-0706
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
CVE-2017-15706
Inconsistent documentation in Apache Tomcat
CVE-2017-7675
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
CVE-2016-6797
Incorrect Authorization in Apache Tomcat
CVE-2022-29885
Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption
CVE-2021-33037
HTTP Request Smuggling in Apache Tomcat
CVE-2021-42340
Missing Release of Resource after Effective Lifetime in Apache Tomcat
CVE-2021-43980
Apache Tomcat Race Condition vulnerability
CVE-2016-0762
Observable Discrepancy in Apache Tomcat
CVE-2017-5664
Improper Handling of Exceptional Conditions in Apache Tomcat
CVE-2016-0763
Improper Verification of Source of a Communication Channel in Apache Tomcat
CVE-2015-5346
Improper Neutralization of Input During Web Page Generation in Apache Tomcat
CVE-2017-5650
Improper Resource Shutdown or Release in Apache Tomcat
CVE-2017-7674
Insufficient Verification of Data Authenticity in Apache Tomcat
CVE-2016-0714
Improper Access Control in Apache Tomcat
CVE-2010-4172
Improper Neutralization of Input During Web Page Generation in Apache Tomcat
CVE-2011-1088
Apache Tomcat allows remote attackers to bypass intended access restrictions
CVE-2010-4476
Apache Tomcat affected by infinite loop in Double.parseDouble method in Java Runtime Environment
CVE-2008-2938
Apache Tomcat Directory Traversal vulnerability
CVE-2022-23181
Race condition in Apache Tomcat
CVE-2021-41079
Infinite loop in Tomcat due to parsing error
CVE-2011-0534
Apache Tomcat does not enforce the maxHttpHeaderSize limit
CVE-2010-2227
Apache Tomcat does not properly handle an invalid Transfer-Encoding header
CVE-2011-5063
Improper Authentication in Apache Tomcat
CVE-2011-5062
Improper Authentication in Apache Tomcat
CVE-2011-3190
Apache Tomcat Allows Remote Attackers to Spoof AJP Requests
CVE-2011-2526
Improper Input Validation in Apache Tomcat
CVE-2011-2481
Apache Tomcat Allows Replacing of XML Parser
CVE-2011-2204
Insertion of Sensitive Information into Log File in Apache Tomcat
CVE-2011-1582
Access restriction bypass in Apache Tomcat
CVE-2011-1184
Authentication Bypass in Apache Tomcat
CVE-2011-1183
Access controll bypass in Apache Tomcat
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes