Apache Tomcat Multiple Vulnerabilities
Release Date:
2 Jul 2026
172
Views
RISK: Medium Risk
TYPE: Servers - Web Servers

Multiple vulnerabilities were identified in Apache Tomcat. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, elevation of privilege and security restriction bypass on the targeted system.
Impact
- Elevation of Privilege
- Security Restriction Bypass
- Cross-Site Scripting
System / Technologies affected
- Apache Tomcat version 9.0.0.M1 to 9.0.118
- Apache Tomcat version 10.1.0-M1 to 10.1.55
- Apache Tomcat version 11.0.0-M1 to 11.0.22
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.119
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.56
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.23
Vulnerability Identifier
Source
Related Link
Share with
