[Git][security-tracker-team/security-tracker][master] Add new tomcat9 issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 26 10:42:01 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
22f31acb by Salvatore Bonaccorso at 2026-08-26T11:41:39+02:00
Add new tomcat9 issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1108,8 +1108,11 @@ CVE-2026-73335 (Android application "Myna Point" is vulnerable to Improper Autho
CVE-2026-73180 (Insufficient Session Expiration vulnerability in Apache Tomcat meant t ...)
- tomcat11 <unfixed>
- tomcat10 <unfixed>
+ - tomcat9 9.0.70-2
+ NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/e617a5d483b78851d289ca8dc1d68c49b541b419 (11.0.25)
NOTE: https://github.com/apache/tomcat/commit/83427cbdb92ca41244dc3d242ca4308ed8ade7d3 (10.1.58)
+ NOTE: https://github.com/apache/tomcat/commit/4b41a73a2f1a16647d7444ad6ee87d41a3ec414b (9.0.121)
CVE-2026-72924 (GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28. ...)
TODO: check
CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect authentication ...)
@@ -1117,18 +1120,27 @@ CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect authentic
CVE-2026-68763 (Uncontrolled Resource Consumption vulnerability in Apache Tomcatvia an ...)
- tomcat11 <unfixed>
- tomcat10 <unfixed>
+ - tomcat9 9.0.70-2
+ NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/2a5ec806971627943db18601203129d9c58d959f (11.0.25)
NOTE: https://github.com/apache/tomcat/commit/19d40615620fe145e88536e2bd63c5f01077c253 (10.1.58)
+ NOTE: https://github.com/apache/tomcat/commit/0747dd58cc631f90e044df246bd2ede6e2b48250 (9.0.121)
CVE-2026-68569 (Improper Authentication vulnerability in Apache Tomcat meant that in s ...)
- tomcat11 <unfixed>
- tomcat10 <unfixed>
+ - tomcat9 9.0.70-2
+ NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/790d6e2c3b4cd201a1fa556a23d5b7504dee18ad (11.0.25)
NOTE: https://github.com/apache/tomcat/commit/3ff06ceb984edc2a3c9e0161b01e833c5e50ed4f (10.1.58)
+ NOTE: https://github.com/apache/tomcat/commit/8efd51f061c026f6339bfa4fe4ef919a04ef130a (9.0.121)
CVE-2026-68525 (Incorrect Authorization vulnerability in Apache Tomcat's FORM authenti ...)
- tomcat11 <unfixed>
- tomcat10 <unfixed>
+ - tomcat9 9.0.70-2
+ NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/10d048e16034ddf12055e0cede0da05b15c823b8 (11.0.25)
NOTE: https://github.com/apache/tomcat/commit/58123aa468a20e2a079b7e0c68a4009e2475c098 (10.1.58)
+ NOTE: https://github.com/apache/tomcat/commit/32f0c38526b4e655ff0c17cd97afedefc624fe43 (9.0.121)
CVE-2026-68515 (OpenEXR is the reference implementation and specification for the EXR ...)
TODO: check
CVE-2026-68514 (OpenEXR is the reference implementation and specification for the EXR ...)
@@ -1138,8 +1150,11 @@ CVE-2026-68513 (OpenEXR is the reference implementation and specification for th
CVE-2026-66422 (Improper Authorization vulnerability in Apache Tomcat cause by securit ...)
- tomcat11 <unfixed>
- tomcat10 <unfixed>
+ - tomcat9 9.0.70-2
+ NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/2c2c510ab10ae7796de6c6f7b70abae85c99d30d (11.0.25)
NOTE: https://github.com/apache/tomcat/commit/49506f6d5ad7cdef211ce1a4026a29183b3df5c7 (10.1.58)
+ NOTE: https://github.com/apache/tomcat/commit/bd05d5ced387da0c967bb232f7e3cd57685d2a7b (9.0.121)
CVE-2026-66153 (The NEService auto-upgrade process insecurely handles temporary files ...)
NOT-FOR-US: SonicWall
CVE-2026-66152 (A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetE ...)
@@ -1147,32 +1162,49 @@ CVE-2026-66152 (A Path traversal vulnerability in OPSWAT tarball in the SonicWal
CVE-2026-65927 (Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag ...)
- tomcat11 <unfixed>
- tomcat10 <unfixed>
+ - tomcat9 9.0.70-2
+ NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/bce83410ffb1542752d52b536257e81a5c8dfcb8 (11.0.25)
NOTE: https://github.com/apache/tomcat/commit/b80929d65be774dc90e378acdda2d16949d1e5f3 (11.0.25)
NOTE: https://github.com/apache/tomcat/commit/3097902177a041a93476a036b9c8419b25d5cc0d (10.1.58)
NOTE: https://github.com/apache/tomcat/commit/7d2ae3952a39db5790dcfd36e5d79c75570a20ee (10.1.58)
+ NOTE: https://github.com/apache/tomcat/commit/ffa86dc683645f784e36ec87236d51ea866dcadf (9.0.121)
+ NOTE: https://github.com/apache/tomcat/commit/b477537e68acfcaa7220f90b512bf8a72bf237dc (9.0.121)
CVE-2026-65905 (Authentication Bypass by Capture-replay vulnerability in Apache Tomcat ...)
- tomcat11 <unfixed>
- tomcat10 <unfixed>
+ - tomcat9 9.0.70-2
+ NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/c5f94ad1726e8399b77eb3fd69c811c1103894d6 (11.0.25)
NOTE: https://github.com/apache/tomcat/commit/1c1a583ba57092206f77c375f45da12c99fb141d (10.1.58)
+ NOTE: https://github.com/apache/tomcat/commit/a31181af45e494b6035575519f6d1d33875f050d (9.0.121)
CVE-2026-65637 (Improper Input Validation vulnerability in Apache Tomcat due to incomp ...)
- tomcat11 <unfixed>
- tomcat10 <unfixed>
+ - tomcat9 9.0.70-2
+ NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/8639b20f045c88f356b887204f52e897399f0de7 (11.0.25)
NOTE: https://github.com/apache/tomcat/commit/40012414df828a56126f76a7339669c7c919aae7 (10.1.58)
+ NOTE: https://github.com/apache/tomcat/commit/b823e88da077f5fa973e34d72359bded9f621e3c (9.0.121)
CVE-2026-65367 (A null pointer dereference was addressed with improved input validatio ...)
NOT-FOR-US: Apple
CVE-2026-65183 (Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apa ...)
- tomcat11 <unfixed>
- tomcat10 <unfixed>
+ - tomcat9 9.0.70-2
+ NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/4fb4523d70258614a00e7501ae0fdf3cdcbc2470 (11.0.25)
NOTE: https://github.com/apache/tomcat/commit/d8bcec9a30788fd887f33890b77ae1b8cd5f1f7e (10.1.58)
+ NOTE: https://github.com/apache/tomcat/commit/0206022f3aae65c5e0f23334b080849fdaaef444 (9.0.121)
+ NOTE: https://github.com/apache/tomcat/commit/07e1b7d3da47a97d2861116f0ba5dd2b4018d256 (9.0.121)
CVE-2026-65182 (Improper Access Control, Incorrect Authorization vulnerability in Apac ...)
- tomcat11 <unfixed>
- tomcat10 <unfixed>
+ - tomcat9 9.0.70-2
+ NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/8bafd79a3b54684e80e9cb1bafd4746aede7d3f5 (11.0.25)
NOTE: https://github.com/apache/tomcat/commit/b79752d2a8578d94743e2a95c50af297f780c0df (10.1.58)
+ NOTE: https://github.com/apache/tomcat/commit/b2c56ec8f20c66773a1a813034ffcdb60841f1cf (9.0.121)
CVE-2026-65105 (NVIDIA NemoClaw for Linux contains a vulnerability in its inference se ...)
NOT-FOR-US: NVIDIA
CVE-2026-65099 (NVIDIA NemoClaw for Linux contains a vulnerability in its command-line ...)
@@ -33654,6 +33686,7 @@ CVE-2026-66299 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat
NOTE: Only affects the WebSocket chat example
NOTE: https://github.com/apache/tomcat/commit/4e8e3f8964e9653bab427bf794e026c69ee80f2b (11.0.25)
NOTE: https://github.com/apache/tomcat/commit/446efef55c69b0cabde1f7e582382cb26e651022 (10.1.58)
+ NOTE: https://github.com/apache/tomcat/commit/f6dda658e4eda2190de96219c182b9a75d27ab06 (9.0.121)
CVE-2026-65882 (Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdl ...)
NOT-FOR-US: Joomla
CVE-2026-65881 (Joomla Extension - joomdle.com - Insecure default configuration allows ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22f31acb065e67a63211cfa4f8b630f6528045e9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22f31acb065e67a63211cfa4f8b630f6528045e9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/b164e1e2/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list