Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:rpm/redhat/tomcat

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. Security Fix(es): * Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990) * tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512) * tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293) * tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. (CVE-2026-42498) * tomcat-coyote: tomcat: Improper Authorization allows security bypass (CVE-2026-43515) * tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) * tomcat: Apache Tomcat: Authentication bypass via missing critical step in JNDIRealm GSSAPI configuration (CVE-2026-55957) * tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) * tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor (CVE-2026-29146) * Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass (CVE-2026-34486) Bug Fix(es) and Enhancement(s): * Remove tomcat clustering JAR from RPM builds (JIRA:RHEL-183993) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor (CVE-2026-29146) * Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass (CVE-2026-34486) Bug Fix(es) and Enhancement(s): * Remove tomcat clustering JAR from RPM builds (JIRA:RHEL-168577) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Multiple security vulnerabilities affecting Apache Tomcat and Apache Commons FileUpload have been addressed in Red Hat Enterprise Linux 8. These include denial of service (DoS) issues via multipart upload, HTTP/2 control frames, and part headers, as well as a security constraint bypass vulnerability. The update resolves several high-severity issues that could impact the availability and security of Tomcat deployments.

Join the discussion
0

Red Hat has issued a moderate severity security advisory for Apache Tomcat in Red Hat Enterprise Linux 8.8 Extended Update Support. The update addresses two vulnerabilities: CVE-2024-50379, a remote code execution (RCE) due to a time-of-check to time-of-use (TOCTOU) issue in JSP compilation, and CVE-2025-24813, which involves potential RCE, information disclosure, or information corruption via partial PUT requests. These vulnerabilities affect Tomcat versions prior to 9.0.87-1.el8_8.4. Red Hat provides updated packages to remediate these issues.

Join the discussion
0

Red Hat has issued a security advisory for Apache Tomcat addressing two vulnerabilities: CVE-2024-50379, a remote code execution (RCE) due to a time-of-check to time-of-use (TOCTOU) issue in JSP compilation, and CVE-2025-24813, which involves potential RCE, information disclosure, or information corruption via partial PUT requests. The update applies to Red Hat Enterprise Linux 9.4 Extended Update Support and related variants. The advisory rates the security impact as moderate and provides updated packages to remediate these issues.

Join the discussion
0

Red Hat has issued a security advisory for Apache Tomcat addressing two vulnerabilities: a time-of-check to time-of-use (TOCTOU) issue in JSP compilation (CVE-2024-50379) that could lead to remote code execution (RCE), and a vulnerability involving partial PUT requests that could result in RCE, information disclosure, or data corruption (CVE-2025-24813). The update is rated with moderate severity and affects Red Hat Enterprise Linux 9.2 Extended Update Support versions. The advisory provides updated packages to remediate these issues.

Join the discussion
0

Red Hat has issued a security advisory for Apache Tomcat addressing two vulnerabilities: CVE-2024-34750, involving improper handling of exceptional conditions, and CVE-2024-38286, a denial of service vulnerability. These issues affect Red Hat Enterprise Linux 9.2 Extended Update Support and related variants. The update is rated as important by Red Hat Product Security. A patch is available to remediate these vulnerabilities.

Join the discussion
0

Red Hat has issued a security advisory for Apache Tomcat addressing two vulnerabilities: CVE-2024-34750 involving improper handling of exceptional conditions, and CVE-2024-38286 related to denial of service. These vulnerabilities affect Red Hat Enterprise Linux 8.8 Extended Update Support versions of Tomcat. The update is rated as Important by Red Hat Product Security. A patch is available to remediate these issues.

Join the discussion
0

Red Hat has issued a security advisory for Apache Tomcat addressing two vulnerabilities: CVE-2024-34750, involving improper handling of exceptional conditions, and CVE-2024-38286, a denial of service vulnerability. These issues affect Red Hat Enterprise Linux 8 versions prior to 8.10.2. The update is rated as important by Red Hat Product Security. A patch is available to remediate these vulnerabilities.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:rpm/redhat/tomcat
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses