Apache Tomcat version lifecycle
runtime · Apache Software Foundation
Current status
Supported version lines, end-of-life status, and latest releases for Apache Tomcat — derived from official vendor sources, not third-party EOL aggregators.
Apache Tomcat is an open-source Jakarta Servlet/JSP container. Version lines, releases, lifecycle, and Java compatibility from tomcat.apache.org and the ASF archive.
Security: 12 tracked advisories · 7 in CISA KEV. Details below — lifecycle and vulnerability status are separate.
Official site →Version lines
12
Supported
3
EOL lines
8
Latest stable
11.0.25
2026-08-18
Releases tracked
550
At a glance
Latest release
11.0.25
Line 11.0
Recommended support line
11.0
standard support
Status
STANDARD SUPPORT
Newest supported: 11.0
EOL
Not published
Exact date not officially published
EOL lines include 10.0, 8.5, 8.0, 7.0, 6.0 (+3 more).
Recommended line: 11.0 (newest supported line with lowest lifecycle risk — not blindly “latest”).
Supported versions
3 currently supported release lines.
End-of-life versions
Historical and unsupported release lines. Exact EOL dates shown only when published by the vendor.
| Version line | Latest release | Lifecycle | EOL | Risk |
|---|---|---|---|---|
| 10.0 | 10.0.27 | end of lifehigh | 2022-10-31 | high |
| 8.5 | 8.5.100 | end of lifehigh | 2024-03-31 | high |
| 8.0 | 8.0.53 | end of lifehigh | 2018-06-30 | high |
| 7.0 | 7.0.109 | end of lifehigh | 2021-03-31 | high |
| 6.0 | 6.0.53 | end of lifehigh | 2016-12-31 | high |
| 5.5 | 5.5.36 | end of lifehigh | 2012-10-01 | high |
| 4.1 | 4.1.40 | end of lifehigh | 2009-06-25 | high |
| 3.3 | 3.3.2 | end of lifehigh | 2004-03-09 | high |
Lifecycle overview
Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.
- 11.0standard supportstandard support
- 10.1standard supportstandard support
- 10.0end of life · EOL 2022-10-31end of life
- 9.0standard support · EOL 2027-03-31standard support
- 8.5end of life · EOL 2024-03-31end of life
- 8.0end of life · EOL 2018-06-30end of life
- 7.0end of life · EOL 2021-03-31end of life
- 6.0end of life · EOL 2016-12-31end of life
- 5.5end of life · EOL 2012-10-01end of life
- 4.1end of life · EOL 2009-06-25end of life
- 3.3end of life · EOL 2004-03-09end of life
Known exploited vulnerabilities
CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.
- CVE-2020-1938Known exploited
Apache Tomcat Improper Privilege Management Vulnerability
- CISA KEV:
- listed · added 2022-03-03 · due 2022-03-17
- Required action:
- Apply updates per vendor instructions.
- CVSS:
- 9.8 (critical) · NVD
- Affected:
- >=1.12.0,<=1.12.0; >=9.0.0,<9.0.31
- Fixed in:
- 9.0.31
- CVE-2017-12617Known exploited
Apache Tomcat Remote Code Execution Vulnerability
- CISA KEV:
- listed · added 2022-03-25 · due 2022-04-15
- Required action:
- Apply updates per vendor instructions.
- CVSS:
- 8.1 (high) · NVD
- CWE:
- CWE-434
- Affected:
- >=9.0.0,<9.0.1
- Fixed in:
- 9.0.1
- CVE-2017-12615Known exploitedRansomware use known
Apache Tomcat on Windows Remote Code Execution Vulnerability
- CISA KEV:
- listed · added 2022-03-25 · due 2022-04-15 · ransomware Known
- Required action:
- Apply updates per vendor instructions.
- CVSS:
- 8.1 (high) · NVD
- CWE:
- CWE-434
- Affected:
- >=7.0.0,<=7.0.79
- CVE-2026-34486Known exploited
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
- CISA KEV:
- listed · added 2026-08-04 · due 2026-08-07
- Required action:
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and C…
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-311, CWE-807
- Affected:
- >=11.0.20,<=11.0.20
- CVE-2025-24813Known exploited
Apache Tomcat Path Equivalence Vulnerability
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
- CISA KEV:
- listed · added 2025-04-01 · due 2025-04-22
- Required action:
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Affected:
- >=11.0.0-milestone9,<11.0.3
- Fixed in:
- 11.0.3
- CVE-2023-44487Known exploited
HTTP/2 Rapid Reset Attack Vulnerability
- CISA KEV:
- listed · added 2023-10-10 · due 2023-10-31
- Required action:
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Affected:
- <2023-10-08; <2.5.0; >=4,<=4; >=4.0,<=4.0; <2023.10.16.00; >=7.0.0,<7.0.12; >=1.27.0,<=1.27.0; <10.5.3; >=1.5,<2.2.0; >=1.0,<1.0; <9.4.0; >=11.0.0-milestone9,<=11.0.0-milestone9; >=9.0.0,<9.2.3; <1.28.0; <1.21.4.3; <2.7.5; >=3.0.0,<=3.3.0; >=1.21.0,<1.21.3; <0.17.0; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<=1.57.0-NA; >=1.0-sp2,<1.1; >=1.19.0,<1.19.1; <=2.427; >=12.0.0,<12.0.2; <4.2.2; <3.4.2; <1.22; <1.26.0; >=2.14.1,<=2.14.1; <4.1.100; <1.57.0; >=1.9.5,<=1.25.2; >=20.0.0,<20.8.1; >=8.0,<=8.0; >=3.0.0-beta3,<2.10.5
- Fixed in:
- 2023-10-08, 2.5.0, 2023.10.16.00, 7.0.12, 10.5.3, 2.2.0, 1.0, 9.4.0, 9.2.3, 1.28.0, 1.21.4.3, 2.7.5, 1.21.3, 0.17.0, 1.58.3, 1.1, 1.19.1, 12.0.2, 4.2.2, 3.4.2, 1.22, 1.26.0, 4.1.100, 1.57.0, 20.8.1, 2.10.5
- CVE-2016-8735Known exploited
Apache Tomcat Remote Code Execution Vulnerability
- CISA KEV:
- listed · added 2023-05-12 · due 2023-06-02
- Required action:
- Apply updates per vendor instructions.
- Affected:
- >=9.0.0-milestone9,<8.5.7
- Fixed in:
- 8.5.7
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- Known vulnerabilities
- 12
- Known exploited
- 7
- Highest CVSS
- 9.8
- CVE-2020-1938Known exploited
Apache Tomcat Improper Privilege Management Vulnerability
- CISA KEV:
- listed · added 2022-03-03 · due 2022-03-17
- Required action:
- Apply updates per vendor instructions.
- CVSS:
- 9.8 (critical) · NVD
- Affected:
- >=1.12.0,<=1.12.0; >=9.0.0,<9.0.31
- Fixed in:
- 9.0.31
- CVE-2017-12617Known exploited
Apache Tomcat Remote Code Execution Vulnerability
- CISA KEV:
- listed · added 2022-03-25 · due 2022-04-15
- Required action:
- Apply updates per vendor instructions.
- CVSS:
- 8.1 (high) · NVD
- CWE:
- CWE-434
- Affected:
- >=9.0.0,<9.0.1
- Fixed in:
- 9.0.1
- CVE-2017-12615Known exploitedRansomware use known
Apache Tomcat on Windows Remote Code Execution Vulnerability
- CISA KEV:
- listed · added 2022-03-25 · due 2022-04-15 · ransomware Known
- Required action:
- Apply updates per vendor instructions.
- CVSS:
- 8.1 (high) · NVD
- CWE:
- CWE-434
- Affected:
- >=7.0.0,<=7.0.79
- CVE-2026-34486Known exploited
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
- CISA KEV:
- listed · added 2026-08-04 · due 2026-08-07
- Required action:
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and C…
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-311, CWE-807
- Affected:
- >=11.0.20,<=11.0.20
- CVE-2025-24813Known exploited
Apache Tomcat Path Equivalence Vulnerability
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
- CISA KEV:
- listed · added 2025-04-01 · due 2025-04-22
- Required action:
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Affected:
- >=11.0.0-milestone9,<11.0.3
- Fixed in:
- 11.0.3
- CVE-2023-44487Known exploited
HTTP/2 Rapid Reset Attack Vulnerability
- CISA KEV:
- listed · added 2023-10-10 · due 2023-10-31
- Required action:
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Affected:
- <2023-10-08; <2.5.0; >=4,<=4; >=4.0,<=4.0; <2023.10.16.00; >=7.0.0,<7.0.12; >=1.27.0,<=1.27.0; <10.5.3; >=1.5,<2.2.0; >=1.0,<1.0; <9.4.0; >=11.0.0-milestone9,<=11.0.0-milestone9; >=9.0.0,<9.2.3; <1.28.0; <1.21.4.3; <2.7.5; >=3.0.0,<=3.3.0; >=1.21.0,<1.21.3; <0.17.0; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<=1.57.0-NA; >=1.0-sp2,<1.1; >=1.19.0,<1.19.1; <=2.427; >=12.0.0,<12.0.2; <4.2.2; <3.4.2; <1.22; <1.26.0; >=2.14.1,<=2.14.1; <4.1.100; <1.57.0; >=1.9.5,<=1.25.2; >=20.0.0,<20.8.1; >=8.0,<=8.0; >=3.0.0-beta3,<2.10.5
- Fixed in:
- 2023-10-08, 2.5.0, 2023.10.16.00, 7.0.12, 10.5.3, 2.2.0, 1.0, 9.4.0, 9.2.3, 1.28.0, 1.21.4.3, 2.7.5, 1.21.3, 0.17.0, 1.58.3, 1.1, 1.19.1, 12.0.2, 4.2.2, 3.4.2, 1.22, 1.26.0, 4.1.100, 1.57.0, 20.8.1, 2.10.5
- CVE-2016-8735Known exploited
Apache Tomcat Remote Code Execution Vulnerability
- CISA KEV:
- listed · added 2023-05-12 · due 2023-06-02
- Required action:
- Apply updates per vendor instructions.
- Affected:
- >=9.0.0-milestone9,<8.5.7
- Fixed in:
- 8.5.7
- CVE-2026-73180
Apache Tomcat: Authenticated WebSocket session survives end of HTTP session
- Affected:
- >=7.0.43,<=7.0.109
- Source:
- OSV source · Advisory
- CVE-2026-68763
Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
- Affected:
- >=8.5.59,<8.5.100
- Fixed in:
- 8.5.100
- Source:
- OSV source · Advisory
- CVE-2026-68569
Apache Tomcat: Principal lookup can fail open in some cases
- Affected:
- >=7.0.0,<=7.0.109
- Source:
- OSV source · Advisory
- CVE-2026-68525
Apache Tomcat: Redirect after FORM auth may bypass method specific constraints
- Affected:
- >=7.0.0,<=7.0.109
- Source:
- OSV source · Advisory
- CVE-2026-66422
Apache Tomcat: Servlet role references can bypass declarative role constraints
- Affected:
- >=7.0.97,<=7.0.109
- Source:
- OSV source · Advisory
Compare versions
Side-by-side view of the most relevant release lines.
Recent releases
Latest release date 2026-08-18 · 3 in last 30 days · 9 in last 90 days
- 2026-08-20
10.1.59
Line 10.1 · standard support - 2026-08-18
11.0.25
Line 11.0 · standard support - 2026-08-18
9.0.121
Line 9.0 · standard support - 2026-07-08
11.0.24
Line 11.0 · standard support - 2026-07-07
10.1.57
Line 10.1 · standard support - 2026-07-07
9.0.120
Line 9.0 · standard support - 2026-06-23
9.0.119
Line 9.0 · standard support - 2026-06-22
11.0.23
Line 11.0 · standard support - 2026-06-22
10.1.56
Line 10.1 · standard support - 2026-05-11
10.1.55
Line 10.1 · standard support
Should I upgrade?
Current versions are supported
The preferred supported release line is Apache Tomcat 11.0 (standard support).
Upgrade planning
Plan upgrades from Apache Tomcat version lines that have newer supported options.
Compatibility
Evidence-backed Apache Tomcat compatibility results from declared requirements — open the Compatibility Explorer for the full matrix.
- ✓Apache Tomcat 11.0 → OpenJDK 21
- ✓Apache Tomcat 11.0 → OpenJDK 26
- ✓Apache Tomcat 11.0 → OpenJDK 25
- ✓Apache Tomcat 11.0 → OpenJDK 17
- ✓Apache Tomcat 10.1 → OpenJDK 21
- ✓Apache Tomcat 10.1 → OpenJDK 26
- ✓Apache Tomcat 10.1 → OpenJDK 25
- ✓Apache Tomcat 10.1 → OpenJDK 17
- ✓Apache Tomcat 10.1 → OpenJDK 11
- ✓Apache Tomcat 10.0 → OpenJDK 21
- ✓Apache Tomcat 10.0 → OpenJDK 26
- ✓Apache Tomcat 10.0 → OpenJDK 25
Java ecosystem
OpenJDK, Spring Boot, and Apache Tomcat work as a stack. CompatHub maps framework Java version requirements from official vendor documentation.
Compatibility within this stack
Data coverage
- Version lines
- 12
- Concrete releases
- 550
- Supported lines
- 3
- EOL lines
- 8
- Lifecycle coverage
- 11/12
- EOL coverage
- 9/12
- Provenance coverage
- 12/12
Data freshness
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Data last checked
- 2026-09-01
- Latest source update
- 2026-09-01
Sources
First-party and other registered sources contributing release and lifecycle facts.
- Apache Tomcat whichversionfirst party · high
Official source: https://tomcat.apache.org/whichversion.html
Last verified 2026-09-01
- OSV.devfirst party
Official source: https://osv.dev
Last checked 2026-09-01
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Last checked 2026-09-01
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Last checked 2026-09-01
- Apache Tomcat GitHub tagsfirst party
Official source: https://api.github.com/repos/apache/tomcat/tags
Last checked 2026-09-01
- Apache Tomcat ASF archivefirst party
Official source: https://archive.apache.org/dist/tomcat/
Last checked 2026-09-01
Version line directory
Complete navigation into detailed version-line pages.
Currently supported
End of life
| Version line | Status | Latest release | Released | EOL |
|---|---|---|---|---|
| 10.0 | end of lifehigh | 10.0.27 | 2022-10-10 | 2022-10-31 |
| 8.5 | end of lifehigh | 8.5.100 | 2024-03-25 | 2024-03-31 |
| 8.0 | end of lifehigh | 8.0.53 | 2018-07-05 | 2018-06-30 |
| 7.0 | end of lifehigh | 7.0.109 | 2021-04-26 | 2021-03-31 |
| 6.0 | end of lifehigh | 6.0.53 | 2017-06-26 | 2016-12-31 |
| 5.5 | end of lifehigh | 5.5.36 | 2012-10-09 | 2012-10-01 |
| 4.1 | end of lifehigh | 4.1.40 | 2009-06-25 | 2009-06-25 |
| 3.3 | end of lifehigh | 3.3.2 | 2004-03-09 | 2004-03-09 |
Archive / no vendor EOL schedule
Lines without a published support schedule from the vendor.
| Version line | Status | Latest release | Released | EOL |
|---|---|---|---|---|
| 5.0 | unknownmedium | 5.0.30 | 2004-11-24 | Not officially published |
