Threats Tagged 'cve-2026-34487'
View all threats tagged with 'cve-2026-34487'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-34487'
Click on any threat for detailed analysis and mitigation recommendations
Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. Security Fix(es): * Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor (CVE-2026-29146) * Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass (CVE-2026-34486) Bug Fix(es) and Enhancement(s): * Remove tomcat clustering JAR from RPM builds (JIRA:RHEL-185571) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/08/2026, 16:38:09 UTC Added: 07/09/2026, 09:38:24 UTC |
0 Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. This release of Red Hat JBoss Web Server 6.2.3 serves as a replacement for Red Hat JBoss Web Server 6.2.2. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section. Security Fix(es): * tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension (CVE-2026-24880) * tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve (CVE-2026-25854) * tomcat: Apache Tomcat: Authentication bypass due to CLIENT_CERT soft fail misconfiguration (CVE-2026-29145) * tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor (CVE-2026-29146) * tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve (CVE-2026-34483) * tomcat: Apache Tomcat: Information disclosure via sensitive data in log files (CVE-2026-34487) * tomcat: Apache Tomcat: Authentication bypass via client certificate misconfiguration (CVE-2026-34500) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/26/2026, 12:55:43 UTC Added: 05/26/2026, 20:58:00 UTC |
0 Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. Join the discussion | CVE Database V5 | 04/13/2026, 10:20:00 UTC Added: 04/09/2026, 20:06:42 UTC |
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0 through 11.0.18, from 10.1.0 through 10.1.52, from 9.0.0 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue. Join the discussion | GCVE Database | 04/13/2026, 10:19:49 UTC Added: 07/16/2026, 10:39:24 UTC |
Showing 1 to 4 of 4 results