Dependency scanning
Check whether org.apache.tomcat:tomcat-catalina is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2025-55668
Apache Tomcat Session Fixation vulnerability
CVE-2023-24998
Apache Commons FileUpload denial of service vulnerability
CVE-2019-0221
Cross-site scripting in Apache Tomcat
CVE-2023-42795
Apache Tomcat Incomplete Cleanup vulnerability
CVE-2023-41080
Apache Tomcat Open Redirect vulnerability
CVE-2026-43515
Apache Tomcat - Security constraints not correctly applied
CVE-2026-43514
Apache Tomcat - AJP secret compared in non-constant time
CVE-2020-9484
Potential remote code execution in Apache Tomcat
CVE-2026-41293
Apache Tomcat - HTTP/2 request headers not validated
CVE-2026-42498
Apache Tomcat - WebSocket authentication header exposure
CVE-2026-43512
Apache Tomcat - Digest authenticator will authenticate any unknown user
CVE-2026-43513
Apache Tomcat: LockOutRealm treats user names as case-sensitive
CVE-2026-41284
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
CVE-2025-55752
Apache Tomcat Vulnerable to Relative Path Traversal
CVE-2025-55754
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
CVE-2025-61795
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
CVE-2026-34483
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
CVE-2026-25854
Apache Tomcat has an Open Redirect vulnerability
CVE-2023-28708
Apache Tomcat vulnerable to Unprotected Transport of Credentials
CVE-2025-52520
Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits
CVE-2025-46701
Apache Tomcat - CGI security constraint bypass
CVE-2023-46589
Apache Tomcat Improper Input Validation vulnerability
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
CVE-2025-49125
Apache Tomcat - Security constraint bypass for pre/post-resources
CVE-2025-31651
Apache Tomcat Rewrite rule bypass
CVE-2024-50379
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
CVE-2024-56337
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
CVE-2025-48988
Apache Tomcat - DoS in multipart upload
CVE-2024-52316
Apache Tomcat - Authentication Bypass
CVE-2025-49124
Apache Tomcat installer for Windows has an untrusted search path vulnerability
CVE-2017-12617
Unrestricted Upload of File with Dangerous Type Apache Tomcat
CVE-2016-8735
Apache Tomcat Improper Access Control vulnerability
CVE-2014-0119
Missing XML Validation in Apache Tomcat
CVE-2014-0096
Improper Input Validation in Apache Tomcat
CVE-2012-5886
Improper Authentication in Apache Tomcat
CVE-2022-45143
Apache Tomcat improperly escapes input from JsonErrorReportValve
CVE-2017-5648
Exposure of Resource to Wrong Sphere in Apache Tomcat
CVE-2016-5388
Improper Access Control in Apache Tomcat
CVE-2017-12616
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes