Safeguard
Tag

apache-tomcat

Safeguard articles tagged "apache-tomcat" — guides, analysis, and best practices for software supply chain and application security.

12 articles

Vulnerability Analysis

CVE-2026-34486: When the Encryption You Configured Doesn't Apply

Apache Tomcat's EncryptInterceptor exists to encrypt cluster replication traffic. CVE-2026-34486 lets that protection be bypassed — the config says encrypted, the wire says otherwise.

Aug 5, 20266 min read
Vulnerability Analysis

Ghostcat: Apache Tomcat AJP File Read and RCE (CVE-2020-1938) Explained

CVE-2020-1938 turned Tomcat's default AJP connector into a file-disclosure and RCE primitive. Here's how the request-attribute abuse works and how to shut it down.

Jul 1, 20266 min read
Security

CVE-2023-42794: The Apache Tomcat Incomplete Cleanup DoS Explained

An unreleased refactoring in Tomcat's bundled Commons FileUpload left temp files undeleted on Windows, risking a disk-exhaustion DoS. Here is what CVE-2023-42794 is and how to fix it.

Jun 26, 20265 min read
Security

CVE-2023-46589: The Tomcat Request Smuggling Flaw, Explained

CVE-2023-46589 lets an attacker smuggle HTTP requests past a reverse proxy by abusing malformed trailer headers in Apache Tomcat. Here is how it works and which versions to run.

Jun 24, 20266 min read
Vulnerability Analysis

CVE-2020-1938 (Ghostcat): File inclusion via Apache Tomca...

Ghostcat (CVE-2020-1938) let attackers read files—and often achieve RCE—via Tomcat's default, unauthenticated AJP connector. Here's the risk, fix, and KEV context.

Jun 23, 20267 min read
Vulnerability Analysis

CVE-2021-33037: HTTP request smuggling in Apache Tomcat

CVE-2021-33037 let malformed HTTP trailers desync Apache Tomcat from front-end proxies, enabling request smuggling. Here's what's affected and how to remediate.

Jun 23, 20267 min read
Vulnerability Analysis

CVE-2019-0232: Remote code execution in Apache Tomcat CGI...

CVE-2019-0232 lets attackers execute arbitrary commands on Windows-hosted Apache Tomcat via the CGI Servlet. Here's the CVSS 9.8 detail, affected versions, and fixes.

Jun 23, 20268 min read
Vulnerability Analysis

CVE-2020-9484: Deserialization RCE via Apache Tomcat Pers...

A deep dive into CVE-2020-9484, the Apache Tomcat PersistenceManager deserialization RCE — affected versions, CVSS/EPSS context, and remediation steps.

Jun 23, 20267 min read
Vulnerability Analysis

CVE-2021-25122: Request mix-up via Apache Tomcat h2c support

CVE-2021-25122 let Apache Tomcat mix up HTTP responses between concurrent users via the h2c upgrade path. Here's the impact, affected versions, and how to remediate.

Jun 22, 20266 min read
Security

CVE-2023-41080: Apache Tomcat Open Redirect in FORM Authentication

CVE-2023-41080 lets a crafted URL trigger an open redirect during FORM login on Tomcat's ROOT web app. Here is the exact condition, affected versions, and the one-line fix path.

Jun 22, 20265 min read
DevSecOps

tomcat-embed-core in Maven: A Security Guide to CVEs and Fixes

The tomcat-embed-core Maven artifact is the embedded Tomcat engine inside most Spring Boot apps, and it has carried several serious CVEs. Here is how to find your version and patch it.

May 20, 20266 min read
Vulnerability Analysis

Ghostcat Apache Tomcat AJP file read/RCE (CVE-2020-1938)

CVE-2020-1938 'Ghostcat' exposes Apache Tomcat's AJP connector to file read and RCE. Here's the ghostcat tomcat AJP vulnerability impact and how to fix it.

Jan 17, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

apache-tomcat — Safeguard Blog