Stateward All advisories →
high
CVE-2026-41284
Maven · org.apache.tomcat.embed:tomcat-embed-core • Maven · org.apache.tomcat:tomcat • Maven · org.apache.tomcat:tomcat-catalina
Summary Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
Severity high EPSS 0.8% (p51) Also known as GHSA-gx5v-xp9w-j4cg#org.apache.tomcat:tomcat, GHSA-gx5v-xp9w-j4cg#org.apache.tomcat:tomcat-catalina, GHSA-gx5v-xp9w-j4cg#org.apache.tomcat.embed:tomcat-embed-core, BIT-tomcat-2026-41284 Published 2026-05-12
Related advisories CVE-2026-41293 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-43512 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-43515 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2025-24813 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2020-1938 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-42498 — high · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-43513 — high · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-34483 — high · Maven/org.apache.tomcat.embed:tomcat-embed-core
Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.
Check my repo