Source: tomcat10
Version: 10.1.55-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for tomcat10.

CVE-2026-65182[0]:
| Improper Access Control, Incorrect Authorization vulnerability in
| Apache Tomcat leads to security constraint bypass if a constraint
| for a longer path is specified before a more restrictive constraint
| for a shorter sub-path.    This issue affects Apache Tomcat: from
| 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from
| 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0
| through 7.0.109.    Users are recommended to upgrade to version
| 11.0.25, 10.1.58, 9.0.121, which fixes the issue.


CVE-2026-65183[1]:
| Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in
| Apache Tomcat when creating unix domain sockets allows an
| unauthorised local user to access the unix domain socket.    This
| issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from
| 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.    Users are
| recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which
| fixes the issue.


CVE-2026-65637[2]:
| Improper Input Validation vulnerability in Apache Tomcat due to
| incomplete fix for CVE-2026-32990.    This issue affects Apache
| Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57,
| from 9.0.115 through 9.0.120.    Users are recommended to upgrade to
| version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.


CVE-2026-65905[3]:
| Authentication Bypass by Capture-replay vulnerability in Apache
| Tomcat's DIGEST authenticator. If, before windowSize requests have
| been made, a client makes a DIGEST  authenticated request with a
| nonceCount on the upper boundary of the  replay window then that
| request is replayable once only while the  associated nonceCount
| remains within the replay window.       This issue affects Apache
| Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through
| 10.1.57, from 9.0.0.M1 through 9.0.120.    The following versions
| were EOL at the time the CVE was created but are  known to be
| affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109.
| Other unsupported versions may also be affected.    Users are
| recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which
| fix the issue.


CVE-2026-65927[4]:
| Off-by-one Error vulnerability in Apache Tomcat impacting the [N]
| flag on the rewrite valves causes rewrite processing to restart at
| the second rule rather than the first rule.        This issue
| affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from
| 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.    The
| following versions were EOL at the time the CVE was created but are
| known to be affected: from 8.5.0 through 8.5.100. Other unsupported
| versions may also be affected.    Users are recommended to upgrade
| to version 11.0.25, 10.1.58 or 9.0.121 which fix the issue.


CVE-2026-66422[5]:
| Improper Authorization vulnerability in Apache Tomcat cause by
| security-role-ref definitions being incorrectly used as role aliases
| within the Realm in additional to the correct usage with
| Request.isUserInRole().    This issue affects Apache Tomcat: from
| 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from
| 9.0.25 through 9.0.120.    The following versions were EOL at the
| time the CVE was created but are  known to be affected: from 8.5.46
| through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported
| versions may also be affected.    Users are recommended to upgrade
| to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.


CVE-2026-68525[6]:
| Incorrect Authorization vulnerability in Apache Tomcat's FORM
| authentication process allows the bypassing of a security constraint
| that limits user has access to a resource POST but not GET.
| This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24,
| from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
| The following versions were EOL at the time the CVE was created but
| are  known to be affected: from 8.5.0 through 8.5.100, from 7.0.0
| through 7.0.109. Other unsupported versions may also be affected.
| Users are recommended to upgrade to version 11.0.25, 10.1.58 or
| 9.0.121, which fixes the issue.


CVE-2026-68569[7]:
| Improper Authentication vulnerability in Apache Tomcat meant that in
| some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be
| authenticated even if the user did not exist in the DataSourceRealm.
| This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24,
| from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
| The following versions were EOL at the time the CVE was created but
| are  known to be affected: from 8.5.0 through 8.5.100, from 7.0.0
| through 7.0.109. Other unsupported versions may also be affected.
| Users are recommended to upgrade to version 11.0.25, 10.1.58 or
| 9.0.121, which fix the issue.


CVE-2026-68763[8]:
| Uncontrolled Resource Consumption vulnerability in Apache Tomcat via
| an allocation leak in the HTTP/2 backlog tracking when a stream is
| reset    This issue affects Apache Tomcat: from 11.0.0-M1 through
| 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through
| 9.0.120.    The following versions were EOL at the time the CVE was
| created but are  known to be affected: from 8.5.59 through
| 8.5.100. Other unsupported versions may also be affected.    Users
| are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121,
| which fix the issue.


CVE-2026-73180[9]:
| Insufficient Session Expiration vulnerability in Apache Tomcat meant
| that if the session ID for an authenticated HTTP session was changed
| after a WebSocket connection had been established under that
| authenticated HTTP session, the WebSokcet session would not be
| closed as required by the Jakarta WebSocket specification when the
| HTTP session ended.    This issue affects Apache Tomcat: from
| 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from
| 9.0.0.M1 through 9.0.120.    The following versions were EOL at the
| time the CVE was created but are  known to be affected: from 8.5.0
| through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported
| versions may also be affected.    Users are recommended to upgrade
| to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-65182
    https://www.cve.org/CVERecord?id=CVE-2026-65182
[1] https://security-tracker.debian.org/tracker/CVE-2026-65183
    https://www.cve.org/CVERecord?id=CVE-2026-65183
[2] https://security-tracker.debian.org/tracker/CVE-2026-65637
    https://www.cve.org/CVERecord?id=CVE-2026-65637
[3] https://security-tracker.debian.org/tracker/CVE-2026-65905
    https://www.cve.org/CVERecord?id=CVE-2026-65905
[4] https://security-tracker.debian.org/tracker/CVE-2026-65927
    https://www.cve.org/CVERecord?id=CVE-2026-65927
[5] https://security-tracker.debian.org/tracker/CVE-2026-66422
    https://www.cve.org/CVERecord?id=CVE-2026-66422
[6] https://security-tracker.debian.org/tracker/CVE-2026-68525
    https://www.cve.org/CVERecord?id=CVE-2026-68525
[7] https://security-tracker.debian.org/tracker/CVE-2026-68569
    https://www.cve.org/CVERecord?id=CVE-2026-68569
[8] https://security-tracker.debian.org/tracker/CVE-2026-68763
    https://www.cve.org/CVERecord?id=CVE-2026-68763
[9] https://security-tracker.debian.org/tracker/CVE-2026-73180
    https://www.cve.org/CVERecord?id=CVE-2026-73180

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore
__
This is the maintainer address of Debian's Java team
<https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-java-maintainers>.
 Please use
[email protected] for discussions and questions.

Reply via email to