[Git][security-tracker-team/security-tracker][master] Track new tomcat10 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 26 10:30:04 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2a1daed5 by Salvatore Bonaccorso at 2026-08-26T11:29:34+02:00
Track new tomcat10 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1107,20 +1107,28 @@ CVE-2026-73335 (Android application "Myna Point" is vulnerable to Improper Autho
 	NOT-FOR-US: Myna Point
 CVE-2026-73180 (Insufficient Session Expiration vulnerability in Apache Tomcat meant t ...)
 	- tomcat11 <unfixed>
+	- tomcat10 <unfixed>
 	NOTE: https://github.com/apache/tomcat/commit/e617a5d483b78851d289ca8dc1d68c49b541b419 (11.0.25)
+	NOTE: https://github.com/apache/tomcat/commit/83427cbdb92ca41244dc3d242ca4308ed8ade7d3 (10.1.58)
 CVE-2026-72924 (GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28. ...)
 	TODO: check
 CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect authentication  ...)
 	TODO: check
 CVE-2026-68763 (Uncontrolled Resource Consumption vulnerability in Apache Tomcatvia an ...)
 	- tomcat11 <unfixed>
+	- tomcat10 <unfixed>
 	NOTE: https://github.com/apache/tomcat/commit/2a5ec806971627943db18601203129d9c58d959f (11.0.25)
+	NOTE: https://github.com/apache/tomcat/commit/19d40615620fe145e88536e2bd63c5f01077c253 (10.1.58)
 CVE-2026-68569 (Improper Authentication vulnerability in Apache Tomcat meant that in s ...)
 	- tomcat11 <unfixed>
+	- tomcat10 <unfixed>
 	NOTE: https://github.com/apache/tomcat/commit/790d6e2c3b4cd201a1fa556a23d5b7504dee18ad (11.0.25)
+	NOTE: https://github.com/apache/tomcat/commit/3ff06ceb984edc2a3c9e0161b01e833c5e50ed4f (10.1.58)
 CVE-2026-68525 (Incorrect Authorization vulnerability in Apache Tomcat's FORM authenti ...)
 	- tomcat11 <unfixed>
+	- tomcat10 <unfixed>
 	NOTE: https://github.com/apache/tomcat/commit/10d048e16034ddf12055e0cede0da05b15c823b8 (11.0.25)
+	NOTE: https://github.com/apache/tomcat/commit/58123aa468a20e2a079b7e0c68a4009e2475c098 (10.1.58)
 CVE-2026-68515 (OpenEXR is the reference implementation and specification for the EXR  ...)
 	TODO: check
 CVE-2026-68514 (OpenEXR is the reference implementation and specification for the EXR  ...)
@@ -1129,30 +1137,42 @@ CVE-2026-68513 (OpenEXR is the reference implementation and specification for th
 	TODO: check
 CVE-2026-66422 (Improper Authorization vulnerability in Apache Tomcat cause by securit ...)
 	- tomcat11 <unfixed>
+	- tomcat10 <unfixed>
 	NOTE: https://github.com/apache/tomcat/commit/2c2c510ab10ae7796de6c6f7b70abae85c99d30d (11.0.25)
-	TODO: check
+	NOTE: https://github.com/apache/tomcat/commit/49506f6d5ad7cdef211ce1a4026a29183b3df5c7 (10.1.58)
 CVE-2026-66153 (The NEService auto-upgrade process insecurely handles temporary files  ...)
 	NOT-FOR-US: SonicWall
 CVE-2026-66152 (A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetE ...)
 	NOT-FOR-US: SonicWall
 CVE-2026-65927 (Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag ...)
 	- tomcat11 <unfixed>
+	- tomcat10 <unfixed>
 	NOTE: https://github.com/apache/tomcat/commit/bce83410ffb1542752d52b536257e81a5c8dfcb8 (11.0.25)
 	NOTE: https://github.com/apache/tomcat/commit/b80929d65be774dc90e378acdda2d16949d1e5f3 (11.0.25)
+	NOTE: https://github.com/apache/tomcat/commit/3097902177a041a93476a036b9c8419b25d5cc0d (10.1.58)
+	NOTE: https://github.com/apache/tomcat/commit/7d2ae3952a39db5790dcfd36e5d79c75570a20ee (10.1.58)
 CVE-2026-65905 (Authentication Bypass by Capture-replay vulnerability in Apache Tomcat ...)
 	- tomcat11 <unfixed>
+	- tomcat10 <unfixed>
 	NOTE: https://github.com/apache/tomcat/commit/c5f94ad1726e8399b77eb3fd69c811c1103894d6 (11.0.25)
+	NOTE: https://github.com/apache/tomcat/commit/1c1a583ba57092206f77c375f45da12c99fb141d (10.1.58)
 CVE-2026-65637 (Improper Input Validation vulnerability in Apache Tomcat due to incomp ...)
 	- tomcat11 <unfixed>
+	- tomcat10 <unfixed>
 	NOTE: https://github.com/apache/tomcat/commit/8639b20f045c88f356b887204f52e897399f0de7 (11.0.25)
+	NOTE: https://github.com/apache/tomcat/commit/40012414df828a56126f76a7339669c7c919aae7 (10.1.58)
 CVE-2026-65367 (A null pointer dereference was addressed with improved input validatio ...)
 	NOT-FOR-US: Apple
 CVE-2026-65183 (Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apa ...)
 	- tomcat11 <unfixed>
+	- tomcat10 <unfixed>
 	NOTE: https://github.com/apache/tomcat/commit/4fb4523d70258614a00e7501ae0fdf3cdcbc2470 (11.0.25)
+	NOTE: https://github.com/apache/tomcat/commit/d8bcec9a30788fd887f33890b77ae1b8cd5f1f7e (10.1.58)
 CVE-2026-65182 (Improper Access Control, Incorrect Authorization vulnerability in Apac ...)
 	- tomcat11 <unfixed>
+	- tomcat10 <unfixed>
 	NOTE: https://github.com/apache/tomcat/commit/8bafd79a3b54684e80e9cb1bafd4746aede7d3f5 (11.0.25)
+	NOTE: https://github.com/apache/tomcat/commit/b79752d2a8578d94743e2a95c50af297f780c0df (10.1.58)
 CVE-2026-65105 (NVIDIA NemoClaw for Linux contains a vulnerability in its inference se ...)
 	NOT-FOR-US: NVIDIA
 CVE-2026-65099 (NVIDIA NemoClaw for Linux contains a vulnerability in its command-line ...)
@@ -33633,6 +33653,7 @@ CVE-2026-66299 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat
 	NOTE: https://lists.apache.org/thread/8owczcc1o8qw1rxmg9gvfk4w2jnh4l5k
 	NOTE: Only affects the WebSocket chat example
 	NOTE: https://github.com/apache/tomcat/commit/4e8e3f8964e9653bab427bf794e026c69ee80f2b (11.0.25)
+	NOTE: https://github.com/apache/tomcat/commit/446efef55c69b0cabde1f7e582382cb26e651022 (10.1.58)
 CVE-2026-65882 (Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdl ...)
 	NOT-FOR-US: Joomla
 CVE-2026-65881 (Joomla Extension - joomdle.com - Insecure default configuration allows ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a1daed51c00f5603719fdc3aa2f7cccd9ce4008

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a1daed51c00f5603719fdc3aa2f7cccd9ce4008
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/9667aac3/attachment.htm>


More information about the debian-security-tracker-commits mailing list