Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
629287
AlmaLinux
4656
Alpaquita
8853
Alpine
4049
Android
3261
Azure Linux
12016
BellSoft Hardened Containers
432
Bitnami
6983
Chainguard
5723
CleanStart
791
CRAN
14
crates.io
2232
Debian
54518
Echo
3188
GHC
3
GIT
81481
GitHub Actions
49
Go
6579
Hackage
30
Hex
57
Julia
508
Linux
15361
Mageia
5877
Maven
6325
MinimOS
26765
npm
217495
NuGet
1658
opam
12
openEuler
6386
openSUSE
12552
OSS-Fuzz
3833
Packagist
6082
Pub
11
PyPI
18692
Red Hat
19393
Rocky Linux
2944
Root
11960
RubyGems
1936
SUSE
20483
SwiftURL
50
Ubuntu
52357
VSCode
18
Wolfi
3674
ID
Packages
Summary
Published
arrow_upward
Attributes
CLEANSTART-2026-IS05941
CleanStart/thingsboard
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native
10 hours ago
Fix available
Severity - 9.8 (Critical)
OESA-2026-1970
openEuler:20.03-LTS-SP4/tomcat
openEuler:22.03-LTS-SP4/tomcat
openEuler:24.03-LTS-SP1/tomcat
openEuler:24.03-LTS-SP2/tomcat
openEuler:24.03-LTS-SP3/tomcat
... 1 more
tomcat security update
5 days ago
Fix available
ROOT-APP-MAVEN-CVE-2026-34487
Root:Maven/io.root.org.apache.tomcat.embed:tomcat-embed-core
CVE-2026-34487 in io.root.org.apache.tomcat.embed:tomcat-embed-core - Patched by Root
6 days ago
Fix available
openSUSE-SU-2026:10547-1
openSUSE:Tumbleweed/tomcat
tomcat-9.0.117-1.1 on GA media
14 Apr
Fix available
openSUSE-SU-2026:10548-1
openSUSE:Tumbleweed/tomcat10
tomcat10-10.1.54-1.1 on GA media
14 Apr
Fix available
openSUSE-SU-2026:10549-1
openSUSE:Tumbleweed/tomcat11
tomcat11-11.0.21-1.1 on GA media
14 Apr
Fix available
BIT-tomcat-2026-34487
Bitnami/tomcat
Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
13 Apr
Fix available
Severity - 7.5 (High)
MGASA-2026-0095
Mageia:9/tomcat
Updated tomcat packages fix security vulnerabilities
12 Apr
Fix available
GHSA-x4m4-345f-5h5g
Maven/org.apache.tomcat.embed:tomcat-embed-core
Maven/org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat-catalina
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
09 Apr
Fix available
Severity - 7.5 (High)
DEBIAN-CVE-2026-34487
Debian:11/tomcat9
Debian:12/tomcat10
Debian:12/tomcat9
Debian:13/tomcat10
Debian:13/tomcat11
... 4 more
See record for full details
09 Apr
Fix available
Severity - 7.5 (High)
UBUNTU-CVE-2026-34487
Ubuntu:16.04:LTS/tomcat6
Ubuntu:25.10/tomcat10
Ubuntu:25.10/tomcat11
Ubuntu:25.10/tomcat9
Ubuntu:Pro:14.04:LTS/tomcat6
... 10 more
See record for full details
09 Apr
No fix available
Severity - 7.5 (High)
Vulnerability Database - OSV