Apache Tomcat version lifecycle

runtime · Apache Software Foundation

Current status

supported

Supported version lines, end-of-life status, and latest releases for Apache Tomcat — derived from official vendor sources, not third-party EOL aggregators.

Apache Tomcat is an open-source Jakarta Servlet/JSP container. Version lines, releases, lifecycle, and Java compatibility from tomcat.apache.org and the ASF archive.

Security: 12 tracked advisories · 7 in CISA KEV. Details below — lifecycle and vulnerability status are separate.

Official site →

Version lines

12

Supported

3

EOL lines

8

Latest stable

11.0.25

2026-08-18

Releases tracked

550

At a glance

Latest release

11.0.25

Line 11.0

Recommended support line

11.0

standard support

Status

STANDARD SUPPORT

Newest supported: 11.0

EOL

Not published

Exact date not officially published

EOL lines include 10.0, 8.5, 8.0, 7.0, 6.0 (+3 more).

Recommended line: 11.0 (newest supported line with lowest lifecycle risk — not blindly “latest”).

Supported versions

3 currently supported release lines.

Version lineLifecycleLatest releaseReleasedEOLRisk
11.0
standard supportlow
11.0.252026-08-18Not officially publishedlow
10.1
standard supportlow
10.1.592026-08-20Not officially publishedlow
9.0
standard supportlow
9.0.1212026-08-182027-03-31low

End-of-life versions

Historical and unsupported release lines. Exact EOL dates shown only when published by the vendor.

Version lineLatest releaseLifecycleEOLRisk
10.010.0.27
end of lifehigh
2022-10-31high
8.58.5.100
end of lifehigh
2024-03-31high
8.08.0.53
end of lifehigh
2018-06-30high
7.07.0.109
end of lifehigh
2021-03-31high
6.06.0.53
end of lifehigh
2016-12-31high
5.55.5.36
end of lifehigh
2012-10-01high
4.14.1.40
end of lifehigh
2009-06-25high
3.33.3.2
end of lifehigh
2004-03-09high

Lifecycle overview

Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.

  • 11.0standard support
    standard support
  • 10.1standard support
    standard support
  • 10.0end of life · EOL 2022-10-31
    end of life
  • 9.0standard support · EOL 2027-03-31
    standard support
  • 8.5end of life · EOL 2024-03-31
    end of life
  • 8.0end of life · EOL 2018-06-30
    end of life
  • 7.0end of life · EOL 2021-03-31
    end of life
  • 6.0end of life · EOL 2016-12-31
    end of life
  • 5.5end of life · EOL 2012-10-01
    end of life
  • 4.1end of life · EOL 2009-06-25
    end of life
  • 3.3end of life · EOL 2004-03-09
    end of life

Known exploited vulnerabilities

CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.

  • CVE-2020-1938Known exploited

    Apache Tomcat Improper Privilege Management Vulnerability

    CISA KEV:
    listed · added 2022-03-03 · due 2022-03-17
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    9.8 (critical) · NVD
    Affected:
    >=1.12.0,<=1.12.0; >=9.0.0,<9.0.31
    Fixed in:
    9.0.31
    Source:
    CISA KEV · Advisory
  • CVE-2017-12617Known exploited

    Apache Tomcat Remote Code Execution Vulnerability

    CISA KEV:
    listed · added 2022-03-25 · due 2022-04-15
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    8.1 (high) · NVD
    CWE:
    CWE-434
    Affected:
    >=9.0.0,<9.0.1
    Fixed in:
    9.0.1
    Source:
    CISA KEV · Advisory
  • CVE-2017-12615Known exploitedRansomware use known

    Apache Tomcat on Windows Remote Code Execution Vulnerability

    CISA KEV:
    listed · added 2022-03-25 · due 2022-04-15 · ransomware Known
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    8.1 (high) · NVD
    CWE:
    CWE-434
    Affected:
    >=7.0.0,<=7.0.79
    Source:
    CISA KEV · Advisory
  • CVE-2026-34486Known exploited

    Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

    Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor

    CISA KEV:
    listed · added 2026-08-04 · due 2026-08-07
    Required action:
    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and C…
    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-311, CWE-807
    Affected:
    >=11.0.20,<=11.0.20
    Source:
    CISA KEV · Advisory
  • CVE-2025-24813Known exploited

    Apache Tomcat Path Equivalence Vulnerability

    Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

    CISA KEV:
    listed · added 2025-04-01 · due 2025-04-22
    Required action:
    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    Affected:
    >=11.0.0-milestone9,<11.0.3
    Fixed in:
    11.0.3
    Source:
    CISA KEV · Advisory
  • CVE-2023-44487Known exploited

    HTTP/2 Rapid Reset Attack Vulnerability

    CISA KEV:
    listed · added 2023-10-10 · due 2023-10-31
    Required action:
    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    Affected:
    <2023-10-08; <2.5.0; >=4,<=4; >=4.0,<=4.0; <2023.10.16.00; >=7.0.0,<7.0.12; >=1.27.0,<=1.27.0; <10.5.3; >=1.5,<2.2.0; >=1.0,<1.0; <9.4.0; >=11.0.0-milestone9,<=11.0.0-milestone9; >=9.0.0,<9.2.3; <1.28.0; <1.21.4.3; <2.7.5; >=3.0.0,<=3.3.0; >=1.21.0,<1.21.3; <0.17.0; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<=1.57.0-NA; >=1.0-sp2,<1.1; >=1.19.0,<1.19.1; <=2.427; >=12.0.0,<12.0.2; <4.2.2; <3.4.2; <1.22; <1.26.0; >=2.14.1,<=2.14.1; <4.1.100; <1.57.0; >=1.9.5,<=1.25.2; >=20.0.0,<20.8.1; >=8.0,<=8.0; >=3.0.0-beta3,<2.10.5
    Fixed in:
    2023-10-08, 2.5.0, 2023.10.16.00, 7.0.12, 10.5.3, 2.2.0, 1.0, 9.4.0, 9.2.3, 1.28.0, 1.21.4.3, 2.7.5, 1.21.3, 0.17.0, 1.58.3, 1.1, 1.19.1, 12.0.2, 4.2.2, 3.4.2, 1.22, 1.26.0, 4.1.100, 1.57.0, 20.8.1, 2.10.5
    Source:
    CISA KEV · Advisory
  • CVE-2016-8735Known exploited

    Apache Tomcat Remote Code Execution Vulnerability

    CISA KEV:
    listed · added 2023-05-12 · due 2023-06-02
    Required action:
    Apply updates per vendor instructions.
    Affected:
    >=9.0.0-milestone9,<8.5.7
    Fixed in:
    8.5.7
    Source:
    CISA KEV · Advisory

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

Known vulnerabilities
12
Known exploited
7
Highest CVSS
9.8
  • CVE-2020-1938Known exploited

    Apache Tomcat Improper Privilege Management Vulnerability

    CISA KEV:
    listed · added 2022-03-03 · due 2022-03-17
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    9.8 (critical) · NVD
    Affected:
    >=1.12.0,<=1.12.0; >=9.0.0,<9.0.31
    Fixed in:
    9.0.31
    Source:
    CISA KEV · Advisory
  • CVE-2017-12617Known exploited

    Apache Tomcat Remote Code Execution Vulnerability

    CISA KEV:
    listed · added 2022-03-25 · due 2022-04-15
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    8.1 (high) · NVD
    CWE:
    CWE-434
    Affected:
    >=9.0.0,<9.0.1
    Fixed in:
    9.0.1
    Source:
    CISA KEV · Advisory
  • CVE-2017-12615Known exploitedRansomware use known

    Apache Tomcat on Windows Remote Code Execution Vulnerability

    CISA KEV:
    listed · added 2022-03-25 · due 2022-04-15 · ransomware Known
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    8.1 (high) · NVD
    CWE:
    CWE-434
    Affected:
    >=7.0.0,<=7.0.79
    Source:
    CISA KEV · Advisory
  • CVE-2026-34486Known exploited

    Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

    Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor

    CISA KEV:
    listed · added 2026-08-04 · due 2026-08-07
    Required action:
    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and C…
    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-311, CWE-807
    Affected:
    >=11.0.20,<=11.0.20
    Source:
    CISA KEV · Advisory
  • CVE-2025-24813Known exploited

    Apache Tomcat Path Equivalence Vulnerability

    Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

    CISA KEV:
    listed · added 2025-04-01 · due 2025-04-22
    Required action:
    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    Affected:
    >=11.0.0-milestone9,<11.0.3
    Fixed in:
    11.0.3
    Source:
    CISA KEV · Advisory
  • CVE-2023-44487Known exploited

    HTTP/2 Rapid Reset Attack Vulnerability

    CISA KEV:
    listed · added 2023-10-10 · due 2023-10-31
    Required action:
    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    Affected:
    <2023-10-08; <2.5.0; >=4,<=4; >=4.0,<=4.0; <2023.10.16.00; >=7.0.0,<7.0.12; >=1.27.0,<=1.27.0; <10.5.3; >=1.5,<2.2.0; >=1.0,<1.0; <9.4.0; >=11.0.0-milestone9,<=11.0.0-milestone9; >=9.0.0,<9.2.3; <1.28.0; <1.21.4.3; <2.7.5; >=3.0.0,<=3.3.0; >=1.21.0,<1.21.3; <0.17.0; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<=1.57.0-NA; >=1.0-sp2,<1.1; >=1.19.0,<1.19.1; <=2.427; >=12.0.0,<12.0.2; <4.2.2; <3.4.2; <1.22; <1.26.0; >=2.14.1,<=2.14.1; <4.1.100; <1.57.0; >=1.9.5,<=1.25.2; >=20.0.0,<20.8.1; >=8.0,<=8.0; >=3.0.0-beta3,<2.10.5
    Fixed in:
    2023-10-08, 2.5.0, 2023.10.16.00, 7.0.12, 10.5.3, 2.2.0, 1.0, 9.4.0, 9.2.3, 1.28.0, 1.21.4.3, 2.7.5, 1.21.3, 0.17.0, 1.58.3, 1.1, 1.19.1, 12.0.2, 4.2.2, 3.4.2, 1.22, 1.26.0, 4.1.100, 1.57.0, 20.8.1, 2.10.5
    Source:
    CISA KEV · Advisory
  • CVE-2016-8735Known exploited

    Apache Tomcat Remote Code Execution Vulnerability

    CISA KEV:
    listed · added 2023-05-12 · due 2023-06-02
    Required action:
    Apply updates per vendor instructions.
    Affected:
    >=9.0.0-milestone9,<8.5.7
    Fixed in:
    8.5.7
    Source:
    CISA KEV · Advisory
  • CVE-2026-73180

    Apache Tomcat: Authenticated WebSocket session survives end of HTTP session

    Affected:
    >=7.0.43,<=7.0.109
    Source:
    OSV source · Advisory
  • CVE-2026-68763

    Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset

    Affected:
    >=8.5.59,<8.5.100
    Fixed in:
    8.5.100
    Source:
    OSV source · Advisory
  • CVE-2026-68569

    Apache Tomcat: Principal lookup can fail open in some cases

    Affected:
    >=7.0.0,<=7.0.109
    Source:
    OSV source · Advisory
  • CVE-2026-68525

    Apache Tomcat: Redirect after FORM auth may bypass method specific constraints

    Affected:
    >=7.0.0,<=7.0.109
    Source:
    OSV source · Advisory
  • CVE-2026-66422

    Apache Tomcat: Servlet role references can bypass declarative role constraints

    Affected:
    >=7.0.97,<=7.0.109
    Source:
    OSV source · Advisory

Compare versions

Side-by-side view of the most relevant release lines.

11.010.19.0
Statusstandard supportstandard supportstandard support
Latest11.0.2510.1.599.0.121
Released2026-08-182026-08-202026-08-18
EOLNot officially publishedNot officially published2027-03-31
Risklowlowlow

Recent releases

Latest release date 2026-08-18 · 3 in last 30 days · 9 in last 90 days

Should I upgrade?

Current versions are supported

The preferred supported release line is Apache Tomcat 11.0 (standard support).

Open upgrade planner →

Upgrade planning

Plan upgrades from Apache Tomcat version lines that have newer supported options.

Compatibility

Evidence-backed Apache Tomcat compatibility results from declared requirements — open the Compatibility Explorer for the full matrix.

Open Compatibility Explorer →

Java ecosystem

OpenJDK, Spring Boot, and Apache Tomcat work as a stack. CompatHub maps framework Java version requirements from official vendor documentation.

Compatibility within this stack

Browse java ecosystem

Data coverage

Version lines
12
Concrete releases
550
Supported lines
3
EOL lines
8
Lifecycle coverage
11/12
EOL coverage
9/12
Provenance coverage
12/12

Data freshness

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Data last checked
2026-09-01
Latest source update
2026-09-01

Sources

First-party and other registered sources contributing release and lifecycle facts.

Version line directory

Complete navigation into detailed version-line pages.

Currently supported

Version lineStatusLatest releaseReleasedEOL
11.0
standard supportlow
11.0.252026-08-18Not officially published
10.1
standard supportlow
10.1.592026-08-20Not officially published
9.0
standard supportlow
9.0.1212026-08-182027-03-31

End of life

Version lineStatusLatest releaseReleasedEOL
10.0
end of lifehigh
10.0.272022-10-102022-10-31
8.5
end of lifehigh
8.5.1002024-03-252024-03-31
8.0
end of lifehigh
8.0.532018-07-052018-06-30
7.0
end of lifehigh
7.0.1092021-04-262021-03-31
6.0
end of lifehigh
6.0.532017-06-262016-12-31
5.5
end of lifehigh
5.5.362012-10-092012-10-01
4.1
end of lifehigh
4.1.402009-06-252009-06-25
3.3
end of lifehigh
3.3.22004-03-092004-03-09

Archive / no vendor EOL schedule

Lines without a published support schedule from the vendor.

Version lineStatusLatest releaseReleasedEOL
5.0
unknownmedium
5.0.302004-11-24Not officially published