[Git][security-tracker-team/security-tracker][master] Add tomcat11 issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 26 10:18:23 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bbacb105 by Salvatore Bonaccorso at 2026-08-26T11:17:18+02:00
Add tomcat11 issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1106,17 +1106,21 @@ CVE-2026-74851 (The Pods WordPress plugin before 3.3.9.1 does not correctly com
CVE-2026-73335 (Android application "Myna Point" is vulnerable to Improper Authorizati ...)
NOT-FOR-US: Myna Point
CVE-2026-73180 (Insufficient Session Expiration vulnerability in Apache Tomcat meant t ...)
- TODO: check
+ - tomcat11 <unfixed>
+ NOTE: https://github.com/apache/tomcat/commit/e617a5d483b78851d289ca8dc1d68c49b541b419 (11.0.25)
CVE-2026-72924 (GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28. ...)
TODO: check
CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect authentication ...)
TODO: check
CVE-2026-68763 (Uncontrolled Resource Consumption vulnerability in Apache Tomcatvia an ...)
- TODO: check
+ - tomcat11 <unfixed>
+ NOTE: https://github.com/apache/tomcat/commit/2a5ec806971627943db18601203129d9c58d959f (11.0.25)
CVE-2026-68569 (Improper Authentication vulnerability in Apache Tomcat meant that in s ...)
- TODO: check
+ - tomcat11 <unfixed>
+ NOTE: https://github.com/apache/tomcat/commit/790d6e2c3b4cd201a1fa556a23d5b7504dee18ad (11.0.25)
CVE-2026-68525 (Incorrect Authorization vulnerability in Apache Tomcat's FORM authenti ...)
- TODO: check
+ - tomcat11 <unfixed>
+ NOTE: https://github.com/apache/tomcat/commit/10d048e16034ddf12055e0cede0da05b15c823b8 (11.0.25)
CVE-2026-68515 (OpenEXR is the reference implementation and specification for the EXR ...)
TODO: check
CVE-2026-68514 (OpenEXR is the reference implementation and specification for the EXR ...)
@@ -1124,23 +1128,31 @@ CVE-2026-68514 (OpenEXR is the reference implementation and specification for th
CVE-2026-68513 (OpenEXR is the reference implementation and specification for the EXR ...)
TODO: check
CVE-2026-66422 (Improper Authorization vulnerability in Apache Tomcat cause by securit ...)
+ - tomcat11 <unfixed>
+ NOTE: https://github.com/apache/tomcat/commit/2c2c510ab10ae7796de6c6f7b70abae85c99d30d (11.0.25)
TODO: check
CVE-2026-66153 (The NEService auto-upgrade process insecurely handles temporary files ...)
NOT-FOR-US: SonicWall
CVE-2026-66152 (A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetE ...)
NOT-FOR-US: SonicWall
CVE-2026-65927 (Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag ...)
- TODO: check
+ - tomcat11 <unfixed>
+ NOTE: https://github.com/apache/tomcat/commit/bce83410ffb1542752d52b536257e81a5c8dfcb8 (11.0.25)
+ NOTE: https://github.com/apache/tomcat/commit/b80929d65be774dc90e378acdda2d16949d1e5f3 (11.0.25)
CVE-2026-65905 (Authentication Bypass by Capture-replay vulnerability in Apache Tomcat ...)
- TODO: check
+ - tomcat11 <unfixed>
+ NOTE: https://github.com/apache/tomcat/commit/c5f94ad1726e8399b77eb3fd69c811c1103894d6 (11.0.25)
CVE-2026-65637 (Improper Input Validation vulnerability in Apache Tomcat due to incomp ...)
- TODO: check
+ - tomcat11 <unfixed>
+ NOTE: https://github.com/apache/tomcat/commit/8639b20f045c88f356b887204f52e897399f0de7 (11.0.25)
CVE-2026-65367 (A null pointer dereference was addressed with improved input validatio ...)
NOT-FOR-US: Apple
CVE-2026-65183 (Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apa ...)
- TODO: check
+ - tomcat11 <unfixed>
+ NOTE: https://github.com/apache/tomcat/commit/4fb4523d70258614a00e7501ae0fdf3cdcbc2470 (11.0.25)
CVE-2026-65182 (Improper Access Control, Incorrect Authorization vulnerability in Apac ...)
- TODO: check
+ - tomcat11 <unfixed>
+ NOTE: https://github.com/apache/tomcat/commit/8bafd79a3b54684e80e9cb1bafd4746aede7d3f5 (11.0.25)
CVE-2026-65105 (NVIDIA NemoClaw for Linux contains a vulnerability in its inference se ...)
NOT-FOR-US: NVIDIA
CVE-2026-65099 (NVIDIA NemoClaw for Linux contains a vulnerability in its command-line ...)
@@ -33620,6 +33632,7 @@ CVE-2026-66299 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://lists.apache.org/thread/8owczcc1o8qw1rxmg9gvfk4w2jnh4l5k
NOTE: Only affects the WebSocket chat example
+ NOTE: https://github.com/apache/tomcat/commit/4e8e3f8964e9653bab427bf794e026c69ee80f2b (11.0.25)
CVE-2026-65882 (Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdl ...)
NOT-FOR-US: Joomla
CVE-2026-65881 (Joomla Extension - joomdle.com - Insecure default configuration allows ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbacb10596aa2129f1e0f885e23855f09b6d867b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbacb10596aa2129f1e0f885e23855f09b6d867b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/03c507cf/attachment.htm>
More information about the debian-security-tracker-commits
mailing list