[Git][security-tracker-team/security-tracker][master] tomcat11 fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sat Aug 8 13:09:37 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9ae64f4a by Moritz Muehlenhoff at 2026-08-08T14:09:03+02:00
tomcat11 fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -22516,7 +22516,7 @@ CVE-2026-59197 (Pillow is a Python imaging library. Prior to 12.3.0, Pillow's pu
 	NOTE: https://github.com/python-pillow/Pillow/pull/9695
 	NOTE: Fixed by: https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1 (12.3.0)
 CVE-2026-59084 (Insufficient Technical Documentation vulnerability in Apache Tomcat si ...)
-	- tomcat11 <unfixed> (bug #1142454)
+	- tomcat11 11.0.24-1 (bug #1142454)
 	- tomcat10 <unfixed> (bug #1142455)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -22524,7 +22524,7 @@ CVE-2026-59084 (Insufficient Technical Documentation vulnerability in Apache Tom
 	NOTE: https://github.com/apache/tomcat/commit/79466463f18cf57704513a5aaa93961bf14c9ef5 (10.1.57)
 	NOTE: https://github.com/apache/tomcat/commit/617d7275782bf58b45f6b7ea82c2edf16660e0b3 (9.0.120)
 CVE-2026-59083 (Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apac ...)
-	- tomcat11 <unfixed> (bug #1142454)
+	- tomcat11 11.0.24-1 (bug #1142454)
 	- tomcat10 <unfixed> (bug #1142455)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -34482,7 +34482,7 @@ CVE-2026-10648 (mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src
 CVE-2026-10647 (The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_nc ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-55956 (Improper Authorization vulnerability in Apache Tomcat leads to securit ...)
-	- tomcat11 <unfixed> (bug #1141337)
+	- tomcat11 11.0.24-1 (bug #1141337)
 	- tomcat10 <unfixed> (bug #1141338)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -34490,7 +34490,7 @@ CVE-2026-55956 (Improper Authorization vulnerability in Apache Tomcat leads to s
 	NOTE: https://github.com/apache/tomcat/commit/9c3b1efb74fd04f77639720af1d48a8f664ad9bb (10.1.56)
 	NOTE: https://github.com/apache/tomcat/commit/a0374c450970760efafbd8806a1db278830ba7bd (9.0.119)
 CVE-2026-55955 (Improper Authentication vulnerability in Apache Tomcat allowed a repla ...)
-	- tomcat11 <unfixed> (bug #1141337)
+	- tomcat11 11.0.24-1 (bug #1141337)
 	- tomcat10 <unfixed> (bug #1141338)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -34498,7 +34498,7 @@ CVE-2026-55955 (Improper Authentication vulnerability in Apache Tomcat allowed a
 	NOTE: https://github.com/apache/tomcat/commit/3a9ff01d2dfaca651edacbda3260e37b98b540d3 (10.1.56)
 	NOTE: https://github.com/apache/tomcat/commit/6a7a432cd7fb4ef358dc12e8da99cf3ab320f3fe (9.0.119)
 CVE-2026-55276 (Always-Incorrect Control Flow Implementation vulnerability in Apache T ...)
-	- tomcat11 <unfixed> (bug #1141337)
+	- tomcat11 11.0.24-1 (bug #1141337)
 	- tomcat10 <unfixed> (bug #1141338)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -34508,7 +34508,7 @@ CVE-2026-55276 (Always-Incorrect Control Flow Implementation vulnerability in Ap
 	NOTE: https://github.com/apache/tomcat/commit/17daf80a738d66a8e6cad05c5e32c2db81500ce1 (10.1.56)
 	NOTE: https://github.com/apache/tomcat/commit/3ca8cae5fd3796b1bd9759e11b0e238161e7a39c (9.0.119)
 CVE-2026-53434 (Detection of Error Condition Without Action vulnerability in Apache To ...)
-	- tomcat11 <unfixed> (bug #1141337)
+	- tomcat11 11.0.24-1 (bug #1141337)
 	- tomcat10 <unfixed> (bug #1141338)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -34516,7 +34516,7 @@ CVE-2026-53434 (Detection of Error Condition Without Action vulnerability in Apa
 	NOTE: https://github.com/apache/tomcat/commit/feec60d6099727db6f911534f6a0f6926ebab070 (10.1.56)
 	NOTE: https://github.com/apache/tomcat/commit/c48ac39c27f4494f8c96b9d56a487253e362d276 (9.0.119)
 CVE-2026-53404 (Always-Incorrect Control Flow Implementation vulnerability in Apache T ...)
-	- tomcat11 <unfixed> (bug #1141337)
+	- tomcat11 11.0.24-1 (bug #1141337)
 	- tomcat10 <unfixed> (bug #1141338)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -34524,7 +34524,7 @@ CVE-2026-53404 (Always-Incorrect Control Flow Implementation vulnerability in Ap
 	NOTE: https://github.com/apache/tomcat/commit/bbb6219fa5ac185060bef7842cee5fb90230ca00 (10.1.56)
 	NOTE: https://github.com/apache/tomcat/commit/fe06ae8a71997061596f54189dae1b1b5da75430 (9.0.119)
 CVE-2026-50229 (Improper Neutralization of Script-Related HTML Tags in a Web Page (Bas ...)
-	- tomcat11 <unfixed> (bug #1141337)
+	- tomcat11 11.0.24-1 (bug #1141337)
 	- tomcat10 <unfixed> (bug #1141338)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9ae64f4acbd63fa928d2aee3d88d9f26af0ff28e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9ae64f4acbd63fa928d2aee3d88d9f26af0ff28e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/2784f1ca/attachment.htm>


More information about the debian-security-tracker-commits mailing list