<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:55:50.466635+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certa-2009-avi-211</id>
    <title>certa-2009-avi-211 — Plusieurs vulnérabilités présentes dans Apache Tomcat permettent à un
utilisateur distant de provoquer un déni de servi…</title>
    <updated>2026-10-03T14:55:50.568314+00:00</updated>
    <content>certa-2009-avi-211</content>
    <link href="https://cve.radiocsirt.org/vuln/certa-2009-avi-211"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-121233</id>
    <title>EUVD-2026-121233</title>
    <updated>2026-10-03T14:55:50.568380+00:00</updated>
    <content>EUVD-2026-121233</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-121233"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2009-0033</id>
    <title>fkie_cve-2009-0033</title>
    <updated>2026-10-03T14:55:50.568396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2009-0033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5cw4-ggx9-36vg</id>
    <title>GHSA-5cw4-ggx9-36vg — Apache Tomcat Denial of Service via Malformed Request Headers</title>
    <updated>2026-10-03T14:55:50.568427+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat</p>
<p>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5cw4-ggx9-36vg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2009-0033</id>
    <title>gsd-2009-0033</title>
    <updated>2026-10-03T14:55:50.568477+00:00</updated>
    <content>gsd-2009-0033</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2009-0033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2009-000037</id>
    <title>jvndb-2009-000037</title>
    <updated>2026-10-03T14:55:50.568490+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Tomcat from The Apache Software Foundation contains a denial of service (DoS) vulnerability.

Apache Tomcat from the Apache Software Foundation is an implementation of the Java Servlet and JavaServer Page (JSP) technologies.
If Tomcat receives a request with an invalid header via the Java AJP connector, it will not return an error and instead closes the AJP connection. In case this connector is member of a mod_jk load balancing worker, this member will be put into an error state and will be blocked from use for approximately one minute. Thus the behavior can be used for a denial of service attack using a carefully crafted request.

According to the developer, unsupported Apache Tomcat 3.x, 4.0.x, and 5.0.x may also be affected.
For more information, refer to the developer's website.

Yoshihito Fukuyama of NTT OSS Center reported this vulnerability to IPA. JPCERT/CC coordinated with The Apache Software Foundation and the vendors under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2009-000037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2009:1164</id>
    <title>RHSA-2009:1164 — Red Hat Security Advisory: tomcat security update</title>
    <updated>2026-10-03T14:55:50.568514+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improve cookie parsing for tomcat5 tomcat request dispatcher information disclosure vulnerability tomcat6 Denial-Of-Service with AJP connection tomcat6 Information disclosure in authentication classes tomcat: XSS in Apache Tomcat calendar application tomcat XML parser information disclosure</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2009:1164"/>
  </entry>
</feed>
