I Use This!
High Activity
Analyzed about 22 hours ago. based on code collected about 23 hours ago.

Project Summary

The Apache Tomcat software is an open source implementation of the Java Servlet, JavaServer Pages, Java Expression Language and Java WebSocket technologies.

Tags

apache http http_server java jsp servlet web web_services

Apache License 2.0
Permitted

Commercial Use

Modify

Distribute

Place Warranty

Sub-License

Private Use

Use Patent Claims

Forbidden

Hold Liable

Use Trademarks

Required

Include Copyright

State Changes

Include License

Include Notice

These details are provided for information only. No information here is legal advice and should not be used as such.

Project Security

Vulnerabilities per Version ( last 10 releases )

Project Vulnerability Report

Security Confidence Index

Poor security track-record
Favorable security track-record

Vulnerability Exposure Index

Many reported vulnerabilities
Few reported vulnerabilities

Did You Know...

  • ...
    there are over 3,000 projects on the Open Hub with security vulnerabilities reported against them
  • ...
    you can embed statistics from Open Hub on your site
  • ...
    in 2016, 47% of companies did not have formal process in place to track OS code
  • ...
    learn about Open Hub updates and features on the Open Hub blog
About Project Security

Languages

Java
81%
XML
9%
XML Schema
7%
10 Other
3%

30 Day Summary

Jul 16 2025 — Aug 15 2025

12 Month Summary

Aug 15 2024 — Aug 15 2025
  • 981 Commits
    Down -100 (9%) from previous 12 months
  • 31 Contributors
    Down 0 (0%) from previous 12 months

Ratings

315 users rate this project:
4.23175
   
4.2/5.0
Click to add your rating
  
Review this Project!
 

Static Analysis ( Generated by Coverity Scan for Apache Tomcat )

Repository URL: https://github.com/apache/tomcat

Version: 10.1.43

2025-07-03
Last Analyzed
243,301
Lines of Code Analyze
0.27
Defect Density

Defects by status for current build

1,290
Total defects
65
Outstanding
828
Fixed

CWE Top 25 defects

ID CWE-Name Number of Defects
327 Use of a Broken or Risky Cryptographic Algorithm 1
798 Use of Hard-coded Credentials 4