Back to blog

// OSSeva Blog

Security

Apache Tomcat CVEs by Release: Which 9.0, 10.1 and 11.0 Version Fixes Each 2025 and 2026 CVE

Randall McClure9 min read

The short answer

Three Tomcat lines get security fixes: 11.0, 10.1 and 9.0, whose current releases are 11.0.26, 10.1.60 and 9.0.122. Tomcat 9.0's end of support has been announced for 31 March 2027. The Tomcat 9 security page lists 68 CVEs made public since 1 January 2025, 52 of them in 2026: 11 rated Important, 12 Moderate and 29 Low by the Tomcat security team. 9.0.122, 10.1.60 and 11.0.26 fix all of them. Tomcat 8.5, 10.0, 8.0 and 7.0 are end of life and get none of these fixes, and the CVE records for many of the 2025 and 2026 issues name 8.5.0 to 8.5.100 as affected.

This guide is a lookup table: find the release you run and see which fixes it has. For the September and August 2026 batches, Ghostcat and the default servlet remote code execution CVEs in detail, see Apache Tomcat vulnerabilities by version: 8.5, 9.0, 10.1, 11.

Tomcat release lines and their CVEs

LineStatusLatest or final releaseNotable CVEs since 2025 that affect itUpstream fix on this line
11.0Supported11.0.26Every CVE in the tables below11.0.26 has all of them
10.1Supported10.1.60Every CVE in the tables below10.1.60 has all of them
9.0Supported; end of support 31 March 20279.0.122Every CVE in the tables below, plus CVE-2025-52434 in the APR/Native connector9.0.122 has all of them
10.0End of life 31 October 202210.0.27Not assessed by the advisories; NVD's configuration for CVE-2026-41284 includes 10.0.0 to 10.0.27No upstream fix on this line
8.5End of life 31 March 20248.5.100CVE-2026-43512, CVE-2026-43515, CVE-2025-66614, CVE-2026-55957, CVE-2026-24880, CVE-2025-48988, CVE-2025-53506 and moreNo upstream fix on this line
8.0End of life 30 June 20188.0.53Not assessed by the advisoriesNo upstream fix on this line
7.0End of life 31 March 20217.0.109CVE-2026-43512, CVE-2026-43515, CVE-2026-55957, CVE-2026-55956, CVE-2026-24880No upstream fix on this line

Status and final releases are from the Tomcat project's "Which version do I want?" page, and the 9.0 date is from its announcement on tomcat.apache.org. After 9.0 ends, a 9.1.x branch continues on the javax namespace; see Tomcat 9 end of support and the 9.1.x branch.

Which release fixes what

Each row is one set of releases. The CVE column lists those rated Important or Moderate by the Tomcat team; Low issues are counted. Fixed versions are the ones the Tomcat security pages list, which can differ from the CVE record: the record for CVE-2026-55957 names 9.0.101 and 10.1.37, while the security pages list it under 9.0.102 and 10.1.39. The release vote for 10.1.58 failed, so 10.1.59 is the first 10.1 release with the August 2026 fixes.

9.010.111.0Important and Moderate CVEsLow
9.0.9910.1.3511.0.3CVE-2025-248130
9.0.10210.1.3911.0.5CVE-2026-55957, made public in June 20260
9.0.10410.1.4011.0.6CVE-2025-316501
9.0.10510.1.4111.0.7None1
9.0.10610.1.4211.0.8CVE-2025-48988, CVE-2025-48976, CVE-2025-49125, CVE-2025-556681
9.0.10710.1.4311.0.9CVE-2025-53506; CVE-2025-52434 on 9.0 only1
9.0.10810.1.4411.0.10CVE-2025-489890
9.0.10910.1.4511.0.11CVE-2025-557521
9.0.11010.1.4711.0.12None1
9.0.11310.1.5011.0.15CVE-2025-666141
9.0.11510.1.5211.0.18CVE-2026-247340
9.0.11610.1.5311.0.20CVE-2026-29146, CVE-2026-29145, CVE-2026-329903
9.0.11710.1.5411.0.21CVE-2026-34486, CVE-2026-345002
9.0.11810.1.5511.0.22CVE-2026-43512, CVE-2026-435155
9.0.11910.1.5611.0.23CVE-2026-559565
9.0.12010.1.5711.0.24None2
9.0.12110.1.5911.0.25CVE-2026-65182, CVE-2026-68569, CVE-2026-65927, CVE-2026-68763, CVE-2026-656376
9.0.12210.1.6011.0.26CVE-2026-76183, CVE-2026-86350, CVE-2026-78383, CVE-2026-77791, CVE-2026-86248, CVE-2026-79677, CVE-2026-735815

A server on 9.0.98 is missing every row, and one on 9.0.110 is missing every row from 9.0.113 down. The row matters more than the date a CVE was published: CVE-2026-55957 was made public in June 2026, but the fix shipped in March 2025, so a server on 9.0.102 or later already has it.

Notable 2025 and 2026 CVEs by release line

The Tomcat team rates many of these Moderate or Low, while the CVSS 3.1 score CISA-ADP added to the NVD record is often much higher. CVSS is NVD's own score where NVD has scored the record, otherwise CISA-ADP's. The last column is what the CVE record or NVD's configuration says about end-of-life lines; the Tomcat security pages themselves list supported lines only.

CVEIssueTomcat ratingCVSSFixed in 9.0 / 10.1 / 11.0End-of-life lines named
CVE-2026-43512DIGEST authentication accepts any user unknown to the Realm who sends the password "null"Moderate9.8 (CISA-ADP)9.0.118 / 10.1.55 / 11.0.228.5.0 to 8.5.100; 7.0.0 to 7.0.109
CVE-2025-66614Different host names in SNI and the Host header bypass client certificate authentication enforced at the connectorModerate9.1 (NVD)9.0.113 / 10.1.50 / 11.0.158.5.0 to 8.5.100
CVE-2026-43515When several constraints set a method for the same extension pattern, only the first is appliedModerate9.1 (CISA-ADP)9.0.118 / 10.1.55 / 11.0.228.5.0 to 8.5.100; 7.0.0 to 7.0.109
CVE-2026-29145CLIENT_CERT authentication passes OCSP checks it should fail when soft fail is disabledModerate9.1 (CISA-ADP)9.0.116 / 10.1.53 / 11.0.20End-of-life Tomcat Native 1.1 and 1.2
CVE-2026-24734OCSP responses are not verified or checked for freshness with Tomcat Native or the FFM connectorModerate7.5 (NVD)9.0.115 / 10.1.52 / 11.0.18End-of-life Tomcat Native 1.1 and 1.2
CVE-2026-24880Unvalidated chunk extensions allow request smuggling behind a proxy that passes CRLFLow7.5 (CISA-ADP)9.0.116 / 10.1.53 / 11.0.208.5.0 to 8.5.100; 7.0.0 to 7.0.109
CVE-2026-41284WebDAV LOCK and PROPFIND bodies have no size limit for unauthenticated usersLow7.5 (CISA-ADP)9.0.118 / 10.1.55 / 11.0.22NVD's configuration includes 8.5, 10.0 and 7.0
CVE-2025-48989HTTP/2 "made you reset" attack exhausts memoryImportant7.5 (CISA-ADP)9.0.108 / 10.1.44 / 11.0.10Older lines "may also be affected"
CVE-2025-53506An HTTP/2 client that never acknowledges the reduced stream limit can open too many streamsImportant7.5 (CISA-ADP)9.0.107 / 10.1.43 / 11.0.98.5.0 to 8.5.100
CVE-2025-48988Multipart requests with many parts exhaust memory; adds maxPartCountImportant7.5 (CISA-ADP)9.0.106 / 10.1.42 / 11.0.88.5.0 to 8.5.100
CVE-2025-49125PreResources and PostResources can be reached through an unexpected, unprotected pathModerate7.5 (CISA-ADP)9.0.106 / 10.1.42 / 11.0.88.5.0 to 8.5.100
CVE-2025-52434Race on connection close crashes the JVM with the APR/Native connectorImportant7.5 (CISA-ADP)9.0.107 / not applicable / not applicable8.5.0 to 8.5.100
CVE-2025-31650Invalid HTTP priority headers leak memory until the JVM runs outImportant7.5 (NVD)9.0.104 / 10.1.40 / 11.0.68.5.90 to 8.5.100
CVE-2026-55957JNDIRealm with a GSSAPI authenticated bind lets a user in without the right passwordImportant7.3 (CISA-ADP)9.0.102 / 10.1.39 / 11.0.58.5.0 to 8.5.100; 7.0.0 to 7.0.109
CVE-2026-55956Security constraints on the default servlet ignore the method they nameModerate6.5 (CISA-ADP)9.0.119 / 10.1.56 / 11.0.238.5.0 to 8.5.100; 7.0.0 to 7.0.109

Most of this list comes down to two features. One is authentication and access control in the container itself: DIGEST, JNDIRealm, CLIENT_CERT with OCSP, and security constraints in web.xml. The other is HTTP/2 and multipart handling, which an unauthenticated client can reach. If you rely on Tomcat's own authentication rather than an identity layer in front of it, the rows rated Moderate deserve the same priority as the Important ones.

The Tomcat CVEs in CISA's KEV catalogue

CISA lists six Tomcat CVEs as exploited. Two are recent: CVE-2025-24813, added on 1 April 2025, and CVE-2026-34486, added on 4 August 2026, fixed in 9.0.99 and 9.0.117 respectively. The other four are older, and the final 8.5 and 7.0 releases already carry their fixes, so they matter on servers that stopped patching early: CVE-2020-1938 (Ghostcat), CVE-2017-12617, CVE-2017-12615, which CISA marks as used in ransomware and which affects Windows servers on 7.0.0 to 7.0.79 with HTTP PUT enabled, fixed in 7.0.81, and CVE-2016-8735, a JmxRemoteLifecycleListener flaw fixed in 7.0.73, 8.5.8 and 9.0.0.M13.

What each line gets

Tomcat 11.0 and 10.1

Both lines are supported, and 11.0.26 and 10.1.60 carry every fix above. 10.1 needs Java 11 or later and 11.0 needs Java 17 or later, and both use the jakarta namespace.

Tomcat 9.0

9.0.122 carries every fix above. Support for 9.0 ends on 31 March 2027, after which the 9.1.x branch carries on without the APR/Native connector, so CVE-2025-52434 is one more reason to move off the APR connector to NIO or NIO2 now. If you are moving to 10.1 instead, see the Tomcat 9 to 10.1 migration guide and Tomcat 9 end of life.

Tomcat 8.5

8.5 reached end of life on 31 March 2024 with 8.5.100. Of the CVEs in the table above, the records for all but CVE-2025-48989, CVE-2026-29145 and CVE-2026-24734 name 8.5 releases as affected, including CVE-2026-43512 at 9.8 and CVE-2025-66614 at 9.1. None has an 8.5 fix. The nearest supported line is 9.0, which keeps the javax namespace. See Tomcat 8.5 end of life.

Tomcat 10.0, 8.0 and 7.0

10.0 ended on 31 October 2022 with 10.0.27, and moving to 10.1 is a small step because both use the jakarta namespace. 7.0 ended on 31 March 2021 with 7.0.109. The records for five of the CVEs above name 7.0 releases as affected, and NVD's configuration for CVE-2026-41284 includes 7.0 too. 8.0 ended in June 2018. See Tomcat 10.0 end of life and Tomcat 7 end of life.

What to do on each line

  • 11.0, 10.1 and 9.0. Move to 11.0.26, 10.1.60 or 9.0.122. Use the fix table to work out what an older patch release is missing.
  • 8.5. Move to 9.0.122 for the same javax namespace, or take patched builds. In the meantime, prefer FORM or an external identity layer over DIGEST, enforce client certificates in the web application rather than only at the connector, limit multipart request sizes at the reverse proxy, and turn off HTTP/2 where clients do not need it.
  • 10.0. Move to 10.1.60, or take patched builds.
  • 7.0 and 8.0. Plan the move to 9.0, which keeps javax. Remove the AJP connector, keep the default servlet read-only, and keep JMX off untrusted networks.

Where OSSeva fits

OSSeva backports Tomcat security fixes to 8.5.x, 9.0.x and 10.0.x and ships them as signed builds that drop into the existing deployment, so a server on 8.5.100 can take the fixes in this guide without a platform migration. They are available now on the Patch, Assure and Operate tiers. Assure adds a hardening review, a connector configuration audit and a Tomcat 10 or 11 migration assessment, and Operate adds 24/7 JVM and Tomcat monitoring with a 15-minute P1 response. See Apache Tomcat support and the Tomcat end of life tracker.

Tags

Apache TomcatCVETomcat 9Tomcat 8.5End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.