Source: tomcat11 Version: 11.0.24-1 Severity: grave Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for tomcat11. CVE-2026-65182[0]: | Improper Access Control, Incorrect Authorization vulnerability in | Apache Tomcat leads to security constraint bypass if a constraint | for a longer path is specified before a more restrictive constraint | for a shorter sub-path. This issue affects Apache Tomcat: from | 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from | 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 | through 7.0.109. Users are recommended to upgrade to version | 11.0.25, 10.1.58, 9.0.121, which fixes the issue. CVE-2026-65183[1]: | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in | Apache Tomcat when creating unix domain sockets allows an | unauthorised local user to access the unix domain socket. This | issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from | 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are | recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which | fixes the issue. CVE-2026-65637[2]: | Improper Input Validation vulnerability in Apache Tomcat due to | incomplete fix for CVE-2026-32990. This issue affects Apache | Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, | from 9.0.115 through 9.0.120. Users are recommended to upgrade to | version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. CVE-2026-65905[3]: | Authentication Bypass by Capture-replay vulnerability in Apache | Tomcat's DIGEST authenticator. If, before windowSize requests have | been made, a client makes a DIGEST authenticated request with a | nonceCount on the upper boundary of the replay window then that | request is replayable once only while the associated nonceCount | remains within the replay window. This issue affects Apache | Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through | 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions | were EOL at the time the CVE was created but are known to be | affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. | Other unsupported versions may also be affected. Users are | recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which | fix the issue. CVE-2026-65927[4]: | Off-by-one Error vulnerability in Apache Tomcat impacting the [N] | flag on the rewrite valves causes rewrite processing to restart at | the second rule rather than the first rule. This issue | affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from | 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The | following versions were EOL at the time the CVE was created but are | known to be affected: from 8.5.0 through 8.5.100. Other unsupported | versions may also be affected. Users are recommended to upgrade | to version 11.0.25, 10.1.58 or 9.0.121 which fix the issue. CVE-2026-66422[5]: | Improper Authorization vulnerability in Apache Tomcat cause by | security-role-ref definitions being incorrectly used as role aliases | within the Realm in additional to the correct usage with | Request.isUserInRole(). This issue affects Apache Tomcat: from | 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from | 9.0.25 through 9.0.120. The following versions were EOL at the | time the CVE was created but are known to be affected: from 8.5.46 | through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported | versions may also be affected. Users are recommended to upgrade | to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. CVE-2026-68525[6]: | Incorrect Authorization vulnerability in Apache Tomcat's FORM | authentication process allows the bypassing of a security constraint | that limits user has access to a resource POST but not GET. | This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, | from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. | The following versions were EOL at the time the CVE was created but | are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 | through 7.0.109. Other unsupported versions may also be affected. | Users are recommended to upgrade to version 11.0.25, 10.1.58 or | 9.0.121, which fixes the issue. CVE-2026-68569[7]: | Improper Authentication vulnerability in Apache Tomcat meant that in | some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be | authenticated even if the user did not exist in the DataSourceRealm. | This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, | from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. | The following versions were EOL at the time the CVE was created but | are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 | through 7.0.109. Other unsupported versions may also be affected. | Users are recommended to upgrade to version 11.0.25, 10.1.58 or | 9.0.121, which fix the issue. CVE-2026-68763[8]: | Uncontrolled Resource Consumption vulnerability in Apache Tomcat via | an allocation leak in the HTTP/2 backlog tracking when a stream is | reset This issue affects Apache Tomcat: from 11.0.0-M1 through | 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through | 9.0.120. The following versions were EOL at the time the CVE was | created but are known to be affected: from 8.5.59 through | 8.5.100. Other unsupported versions may also be affected. Users | are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, | which fix the issue. CVE-2026-73180[9]: | Insufficient Session Expiration vulnerability in Apache Tomcat meant | that if the session ID for an authenticated HTTP session was changed | after a WebSocket connection had been established under that | authenticated HTTP session, the WebSokcet session would not be | closed as required by the Jakarta WebSocket specification when the | HTTP session ended. This issue affects Apache Tomcat: from | 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from | 9.0.0.M1 through 9.0.120. The following versions were EOL at the | time the CVE was created but are known to be affected: from 8.5.0 | through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported | versions may also be affected. Users are recommended to upgrade | to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-65182 https://www.cve.org/CVERecord?id=CVE-2026-65182 [1] https://security-tracker.debian.org/tracker/CVE-2026-65183 https://www.cve.org/CVERecord?id=CVE-2026-65183 [2] https://security-tracker.debian.org/tracker/CVE-2026-65637 https://www.cve.org/CVERecord?id=CVE-2026-65637 [3] https://security-tracker.debian.org/tracker/CVE-2026-65905 https://www.cve.org/CVERecord?id=CVE-2026-65905 [4] https://security-tracker.debian.org/tracker/CVE-2026-65927 https://www.cve.org/CVERecord?id=CVE-2026-65927 [5] https://security-tracker.debian.org/tracker/CVE-2026-66422 https://www.cve.org/CVERecord?id=CVE-2026-66422 [6] https://security-tracker.debian.org/tracker/CVE-2026-68525 https://www.cve.org/CVERecord?id=CVE-2026-68525 [7] https://security-tracker.debian.org/tracker/CVE-2026-68569 https://www.cve.org/CVERecord?id=CVE-2026-68569 [8] https://security-tracker.debian.org/tracker/CVE-2026-68763 https://www.cve.org/CVERecord?id=CVE-2026-68763 [9] https://security-tracker.debian.org/tracker/CVE-2026-73180 https://www.cve.org/CVERecord?id=CVE-2026-73180 Please adjust the affected versions in the BTS as needed. Regards, Salvatore __ This is the maintainer address of Debian's Java team <https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-java-maintainers>. Please use [email protected] for discussions and questions.
