Stateward All advisories →
medium
CVE-2025-49124
Maven · org.apache.tomcat.embed:tomcat-embed-core • Maven · org.apache.tomcat:tomcat • Maven · org.apache.tomcat:tomcat-catalina
Summary Apache Tomcat installer for Windows has an untrusted search path vulnerability
Severity medium EPSS 0.3% (p26) Also known as GHSA-42wg-hm62-jcwg#org.apache.tomcat:tomcat, GHSA-42wg-hm62-jcwg#org.apache.tomcat:tomcat-catalina, GHSA-42wg-hm62-jcwg#org.apache.tomcat.embed:tomcat-embed-core, BIT-tomcat-2025-49124 Published 2025-06-16
Related advisories CVE-2026-41293 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-43512 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-43515 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2025-24813 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2020-1938 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-41284 — high · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-42498 — high · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-43513 — high · Maven/org.apache.tomcat.embed:tomcat-embed-core
Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.
Check my repo