Apache Tomcat 5.0 lifecycle

Current status

unknownmedium

Lifecycle information for Apache Tomcat 5.0 is incomplete in the available first-party sources.

Security: 2 tracked advisories affecting this line · 1 in CISA KEV. Details below — lifecycle and vulnerability status are separate.

Official lifecycle source: OSV.dev

Support phase
unknown
End of life
Not officially published
Latest release
5.0.30
Released
24 Nov 2004

At a glance

Version line
5.0
Initial release
29 Aug 2004
Lifecycle phase
unknown
Latest stable
5.0.30
Latest release date
24 Nov 2004
EOL
Not officially published
Risk
medium
Releases tracked
2

Lifecycle timeline

Phases from published LifecyclePeriod records. Missing phases are not inferred.

Lifecycle information is incomplete in the available first-party sources.

Lifecycle information for Apache Tomcat 5.0 is incomplete in the available first-party sources.

Upgrade options

Newer supported Apache Tomcat version lines from CompatHub lifecycle data. Compatibility and security context use existing evidence only.

You are on Apache Tomcat 5.0

UNKNOWN

Supported upgrade options

Open full upgrade planner for Apache Tomcat 5.0

Known exploited vulnerabilities

CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.

  • CVE-2023-44487Known exploited

    HTTP/2 Rapid Reset Attack Vulnerability

    CISA KEV:
    listed · added 2023-10-10 · due 2023-10-31
    Required action:
    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    Affected:
    <10.5.3; <9.4.0
    Fixed in:
    10.5.3, 9.4.0
    Source:
    CISA KEV · Advisory

Security

Advisories affecting Apache Tomcat 5.0 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
2
Known exploited
1
Highest CVSS
  • CVE-2023-44487Known exploited

    HTTP/2 Rapid Reset Attack Vulnerability

    CISA KEV:
    listed · added 2023-10-10 · due 2023-10-31
    Required action:
    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    Affected:
    <10.5.3; <9.4.0
    Fixed in:
    10.5.3, 9.4.0
    Source:
    CISA KEV · Advisory
  • CVE-2021-33037
    Affected:
    <=10.0.6
    Source:
    OSV source · Advisory

Latest release

Previous releases

  • 5.0.28

    29 Aug 2004

Release history

2 concrete releases tracked for this line.

VersionRelease dateChannelSource
5.0.3024 Nov 2004stableSource
5.0.2829 Aug 2004stableSource

Release activity

Total releases
2
Last 30 days
0
Last 90 days
0
Most recent
24 Nov 2004

Should I use this version?

Lifecycle status unclear

CompatHub does not currently have a clear support status for Apache Tomcat 5.0.

Version comparison

Compact comparison against the nearest relevant release lines.

5.011.0
Statusunknownstandard support
Latest release5.0.3011.0.25
EOLNot publishedNot published
Riskmediumlow

Sources

Where this information comes from.

Lifecycle sources

Release sources

Data coverage

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Releases tracked
2
Lifecycle periods
0
EOL
Not officially published
Provenance records
1
Data last checked
1 Sept 2026
Latest source update
1 Sept 2026

Lifecycle information is incomplete in the available first-party sources.

EOL: Not officially published

Other Apache Tomcat versions