Dependency scanning
Check whether org.apache.tomcat:tomcat-coyote is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-38286
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
CVE-2025-52434
Apache Tomcat is vulnerable to resource exhaustion when using the APR/Native connector
CVE-2026-24733
Apache Tomcat - Security constraint bypass with HTTP/0.9
CVE-2024-21733
Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2023-24998
Apache Commons FileUpload denial of service vulnerability
CVE-2023-45648
Apache Tomcat Improper Input Validation vulnerability
CVE-2025-66614
Apache Tomcat - Client certificate verification bypass
CVE-2021-25122
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
CVE-2026-29129
Apache Tomcat: Configured cipher preference order not preserved
CVE-2026-24880
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
CVE-2020-13934
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
CVE-2019-0199
Apache Tomcat Denial of Service vulnerability
CVE-2023-44487
HTTP/2 Stream Cancellation Attack
CVE-2025-48989
Apache Tomcat Improper Resource Shutdown or Release vulnerability
CVE-2026-32990
Apache Tomcat has an Improper Input Validation vulnerability
CVE-2023-28709
Apache Tomcat - Fix for CVE-2023-24998 was incomplete
CVE-2026-24734
Apache Tomcat has an Improper Input Validation vulnerability
CVE-2025-53506
Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams
CVE-2024-24549
Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
CVE-2025-31650
Apache Tomcat Denial of Service via invalid HTTP priority header
CVE-2024-34750
Apache Tomcat - Denial of Service
CVE-2014-0075
Integer Overflow or Wraparound in Apache Tomcat
CVE-2023-42794
Apache Tomcat Incomplete Cleanup vulnerability
CVE-2024-52317
Apache Tomcat Request and/or response mix-up
CVE-2014-0095
Denial of service in Apache Tomcat
CVE-2023-34981
Apache Tomcat vulnerable to information leak
CVE-2022-42252
Apache Tomcat may reject request containing invalid Content-Length header
CVE-2017-5651
Expected Behavior Violation in Apache Tomcat
CVE-2020-17527
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
CVE-2016-6816
Improper Input Validation in Apache Tomcat
CVE-2020-13943
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes