Severity: low
Affected versions:
- Apache Tomcat 11.0.0-M1 through 11.0.6 - Apache Tomcat 10.1.0-M1 through 10.1.40 - Apache Tomcat 9.0.0.M1 through 9.0.104
Description:
Credit:
Greg K (https://github.com/gregk4sec) (finder)
References:
https://lists.apache.org/thread/xhqqk9w5q45srcdqhogdk04lhdscv30j https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2025-46701
Severity: low
Affected versions:
- Apache Tomcat 11.0.0-M1 through 11.0.5 - Apache Tomcat 10.1.0-M1 through 10.1.39 - Apache Tomcat 9.0.0.M1 through 9.0.102
Description: for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed.
Credit:
COSCO Shipping Lines DIC (finder)
References:
https://lists.apache.org/list.html?announce () tomcat apache org https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2025-31651
Severity: important
Affected versions:
- Apache Tomcat 9.0.76 through 9.0.102 - Apache Tomcat 10.1.10 through 10.1.39 - Apache Tomcat 11.0.0-M2 through 11.0.5
Description:
References:
https://lists.apache.org/thread/j6zzk0y3yym9pzfzkq5vcyxzz0yzh826 https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2025-31650
USN-7469-1 fixed a vulnerability in Apache Traffic Server. This update provides the corresponding updates for Apache Tomcat. Original advisory details: It was discovered that Apache Traffic Server exhibited poor server resource management in its HTTP/2 protocol. An attacker could possibly use this issue to cause Apache Traffic Server to crash, resulting in a denial of service.
When a new critical vulnerability appears, don't just react to the score. Take CVE-2025-24813 (Tomcat) as an example:
Look at the Scores: Start with CVSS and EPSS CVE-2025-24813 had a 9.8 CVSS and 99th percentile EPSS – high severity, actively exploited.
Read the Description: Understand how it works. What conditions are needed?
For CVE-2025-24813, the key was a specific non-default Tomcat configuration requirement. We found a blog post detailing the exact Tomcat setting to search for. We searched our version control to see if that specific configuration was enabled anywhere. It wasn’t. So while it was a critical it appeared that it presented zero risk to us.
If you have a threat intel group or service (like Mandiant), check their assessment. Mandiant rated CVE-2025-24813 as aMedium, due to the uncommon non-default configuration. This multi-step approach gives a far more accurate picture of your actual risk than relying on scores alone.
Severity: important
Affected versions:
- Apache Tomcat 11.0.0-M1 through 11.0.2 - Apache Tomcat 10.1.0-M1 through 10.1.34 - Apache Tomcat 9.0.0.M1 through 9.0.98
Description:
- writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default)
Credit:
COSCO Shipping Lines DIC (finder) sw0rd1ight (https://github.com/sw0rd1ight) (finder)
References:
https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2025-24813
Severity: important
Affected versions:
- Apache Tomcat 11.0.0-M1 through 11.0.1 - Apache Tomcat 10.1.0-M1 through 10.1.33 - Apache Tomcat 9.0.0.M1 through 9.0.97
Description:
The mitigation for CVE-2024-50379 was incomplete. - running on Java 8 or Java 11: the system property sun.io.useCanonCaches must be explicitly set to false (it defaults to true) - running on Java 17: the system property sun.io.useCanonCaches, if set, must be set to false (it defaults to false) - running on Java 21 onwards: no further configuration is required (the system property and the problematic cache have been removed) Credit: References:
https://www.cve.org/CVERecord?id=CVE-2024-50379 https://lists.apache.org/thread/b2b9qrgjrz1kvo4ym8y2wkfdvwoq6qbp https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2024-56337
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97
Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.08 Should that last fixed version be 9.0.98 ?
Nick
On 17/12/2024 16:23, Agostino Sarubbo wrote: On martedì 17 dicembre 2024 13:46:54 CET Mark Thomas wrote:
> - Apache Tomcat 9.0.0.M1 through 9.9.97
I think this is 9.0.97 instead of 9.9.97 Yes, that is correct. I've submitted a correction to cve.org.
Kind regards,
Mark
On martedì 17 dicembre 2024 13:46:54 CET Mark Thomas wrote: - Apache Tomcat 9.0.0.M1 through 9.9.97 I think this is 9.0.97 instead of 9.9.97
Agostino
Severity: low
Affected versions:
- Apache Tomcat 11.0.0-M1 through 11.0.1 - Apache Tomcat 10.1.0-M1 through 10.1.33 - Apache Tomcat 9.0.0.M1 through 9.9.97
Description:
References:
https://lists.apache.org/thread/tdtbbxpg5trdwc2wnopcth9ccvdftq2n https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2024-54677
Severity: important
Affected versions:
- Apache Tomcat 11.0.0-M1 through 11.0.1 - Apache Tomcat 10.1.0-M1 through 10.1.33 - Apache Tomcat 9.0.0.M1 through 9.0.97
Description:
Credit:
Nacl, WHOAMI, Yemoli and Ruozhi (finder)
References:
https://lists.apache.org/thread/y6lj6q1xnp822g6ro70tn19sgtjmr80r https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2024-50379
Severity: important
Affected versions:
- Apache Tomcat 11.0.0 - Apache Tomcat 10.1.31 - Apache Tomcat 9.0.96
Description:
Incorrect object recycling and reuse vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Note: 10.1.32 includes the fix but was not released
References:
https://lists.apache.org/thread/co243cw1nlh6p521c5265cm839wkqdp9 https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2024-52318
Description: The fix for improvement 69333 caused pooled JSP tags not to be released after use which in turn could cause output of some tags not to escaped as expected. This unescaped output could lead to XSS.
Versions Affected: - Apache Tomcat 11.0.0 - Apache Tomcat 10.1.31 - Apache Tomcat 9.0.96
Mitigation: Users of the affected versions should apply one of the following mitigations: - Upgrade to Apache Tomcat 11.0.1 or later - Upgrade to Apache Tomcat 10.1.33 or later Note: 10.1.32 was not released - Upgrade to Apache Tomcat 9.0.97 or later
Severity: important
Affected versions:
- Apache Tomcat 11.0.0-M23 through 11.0.0-M26 - Apache Tomcat 10.1.27 through 10.1.30 - Apache Tomcat 9.0.92 through 9.0.95
Description: could lead to request and/or response mix-up between users.
References:
https://lists.apache.org/thread/ty376mrxy1mmxtw3ogo53nc9l3co3dfs https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2024-52317
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users.
This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.
Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
Severity: low
Affected versions:
- Apache Tomcat 11.0.0-M1 through 11.0.0-M26 - Apache Tomcat 10.1.0-M1 through 10.1.30 - Apache Tomcat 9.0.0-M1 through 9.0.95
Description:
References:
https://lists.apache.org/thread/lopzlqh91jj9n334g02om08sbysdb928 https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2024-52316
Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root
Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
Affected versions:
- Apache Tomcat 11.0.0-M1 through 11.0.0-M20 - Apache Tomcat 10.1.0-M1 through 10.1.24 - Apache Tomcat 9.0.13 through 9.0.89
Description:
Credit:
Ozaki, North Grid Corporation (reporter)
References:
https://lists.apache.org/thread/wms60cvbsz3fpbz9psxtfx8r41jl6d4s https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2024-38286
Timeline:
2024-06-04: Issue reported to Apache Tomcat Security Team
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89.
Users are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue.