Binary distribution of Apache Tomcat
100%
Total Score
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-32990 org.apache.tomcat:tomcat is vulnerable to Improper Input Validation in versions 9.0.113 - 9.0.116, 10.1.50 - 10.1.53 and 11.0.15 - 11.0.18. | 9.0.113 - 9.0.11610.1.50 - 10.1.5311.0.15 - 11.0.18 | Medium |
CVE-2026-29129 org.apache.tomcat:tomcat is vulnerable to Use of a Broken or Risky Cryptographic Algorithm in versions 9.0.114 - 9.0.116, 10.1.51 - 10.1.53 and 11.0.16 - 11.0.20. | 9.0.114 - 9.0.11610.1.51 - 10.1.5311.0.16 - 11.0.20 | High |
CVE-2026-29145 org.apache.tomcat:tomcat is vulnerable to Improper Authentication in versions 9.0.83 - 9.0.116, 10.1.0-M7 - 10.1.53 and 11.0.0-M1 - 11.0.20. | 9.0.83 - 9.0.11610.1.0-M7 - 10.1.5311.0.0-M1 - 11.0.20 | Critical |
CVE-2026-34486 org.apache.tomcat:tomcat is vulnerable to Missing Encryption of Sensitive Data in versions 11.0.20 - 11.0.20, 10.1.53 - 10.1.53 and 9.0.116 - 9.0.116. | 9.0.116 - 9.0.11610.1.53 - 10.1.5311.0.20 - 11.0.20 | High |
CVE-2026-34487 org.apache.tomcat:tomcat is vulnerable to Insertion of Sensitive Information into Log File in versions 9.0.13 - 9.0.117, 10.1.0-M1 - 10.1.54 and 11.0.0-M1 - 11.0.21. | 9.0.13 - 9.0.11710.1.0-M1 - 10.1.5411.0.0-M1 - 11.0.21 | High |
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant