[Git][security-tracker-team/security-tracker][master] Add bug references for tomcat issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 26 20:28:26 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4f87f935 by Salvatore Bonaccorso at 2026-08-26T21:28:13+02:00
Add bug references for tomcat issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1559,8 +1559,8 @@ CVE-2026-74851 (The Pods  WordPress plugin before 3.3.9.1 does not correctly com
 CVE-2026-73335 (Android application "Myna Point" is vulnerable to Improper Authorizati ...)
 	NOT-FOR-US: Myna Point
 CVE-2026-73180 (Insufficient Session Expiration vulnerability in Apache Tomcat meant t ...)
-	- tomcat11 <unfixed>
-	- tomcat10 <unfixed>
+	- tomcat11 <unfixed> (bug #1145698)
+	- tomcat10 <unfixed> (bug #1145699)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/e617a5d483b78851d289ca8dc1d68c49b541b419 (11.0.25)
@@ -1574,24 +1574,24 @@ CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect authentic
 	NOTE: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/security/advisories/GHSA-8r7r-wh7x-27ff
 	NOTE: Fixed by: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/commit/abb47dc5e6012ea05eda0b7979cc6bd41904011b (v1.10.4)
 CVE-2026-68763 (Uncontrolled Resource Consumption vulnerability in Apache Tomcatvia an ...)
-	- tomcat11 <unfixed>
-	- tomcat10 <unfixed>
+	- tomcat11 <unfixed> (bug #1145698)
+	- tomcat10 <unfixed> (bug #1145699)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/2a5ec806971627943db18601203129d9c58d959f (11.0.25)
 	NOTE: https://github.com/apache/tomcat/commit/19d40615620fe145e88536e2bd63c5f01077c253 (10.1.58)
 	NOTE: https://github.com/apache/tomcat/commit/0747dd58cc631f90e044df246bd2ede6e2b48250 (9.0.121)
 CVE-2026-68569 (Improper Authentication vulnerability in Apache Tomcat meant that in s ...)
-	- tomcat11 <unfixed>
-	- tomcat10 <unfixed>
+	- tomcat11 <unfixed> (bug #1145698)
+	- tomcat10 <unfixed> (bug #1145699)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/790d6e2c3b4cd201a1fa556a23d5b7504dee18ad (11.0.25)
 	NOTE: https://github.com/apache/tomcat/commit/3ff06ceb984edc2a3c9e0161b01e833c5e50ed4f (10.1.58)
 	NOTE: https://github.com/apache/tomcat/commit/8efd51f061c026f6339bfa4fe4ef919a04ef130a (9.0.121)
 CVE-2026-68525 (Incorrect Authorization vulnerability in Apache Tomcat's FORM authenti ...)
-	- tomcat11 <unfixed>
-	- tomcat10 <unfixed>
+	- tomcat11 <unfixed> (bug #1145698)
+	- tomcat10 <unfixed> (bug #1145699)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/10d048e16034ddf12055e0cede0da05b15c823b8 (11.0.25)
@@ -1614,8 +1614,8 @@ CVE-2026-68513 (OpenEXR is the reference implementation and specification for th
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/c1f3ec0d91cfa5a8035ecd00920835ac76e01640 (v3.4.14-rc)
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/d134e3cd81a2e343f2919e86bf949f576b1ab16a (v3.3.13-rc)
 CVE-2026-66422 (Improper Authorization vulnerability in Apache Tomcat cause by securit ...)
-	- tomcat11 <unfixed>
-	- tomcat10 <unfixed>
+	- tomcat11 <unfixed> (bug #1145698)
+	- tomcat10 <unfixed> (bug #1145699)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/2c2c510ab10ae7796de6c6f7b70abae85c99d30d (11.0.25)
@@ -1626,8 +1626,8 @@ CVE-2026-66153 (The NEService auto-upgrade process insecurely handles temporary
 CVE-2026-66152 (A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetE ...)
 	NOT-FOR-US: SonicWall
 CVE-2026-65927 (Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag ...)
-	- tomcat11 <unfixed>
-	- tomcat10 <unfixed>
+	- tomcat11 <unfixed> (bug #1145698)
+	- tomcat10 <unfixed> (bug #1145699)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/bce83410ffb1542752d52b536257e81a5c8dfcb8 (11.0.25)
@@ -1637,16 +1637,16 @@ CVE-2026-65927 (Off-by-one Error vulnerability in Apache Tomcat impacting the [N
 	NOTE: https://github.com/apache/tomcat/commit/ffa86dc683645f784e36ec87236d51ea866dcadf (9.0.121)
 	NOTE: https://github.com/apache/tomcat/commit/b477537e68acfcaa7220f90b512bf8a72bf237dc (9.0.121)
 CVE-2026-65905 (Authentication Bypass by Capture-replay vulnerability in Apache Tomcat ...)
-	- tomcat11 <unfixed>
-	- tomcat10 <unfixed>
+	- tomcat11 <unfixed> (bug #1145698)
+	- tomcat10 <unfixed> (bug #1145699)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/c5f94ad1726e8399b77eb3fd69c811c1103894d6 (11.0.25)
 	NOTE: https://github.com/apache/tomcat/commit/1c1a583ba57092206f77c375f45da12c99fb141d (10.1.58)
 	NOTE: https://github.com/apache/tomcat/commit/a31181af45e494b6035575519f6d1d33875f050d (9.0.121)
 CVE-2026-65637 (Improper Input Validation vulnerability in Apache Tomcat due to incomp ...)
-	- tomcat11 <unfixed>
-	- tomcat10 <unfixed>
+	- tomcat11 <unfixed> (bug #1145698)
+	- tomcat10 <unfixed> (bug #1145699)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/8639b20f045c88f356b887204f52e897399f0de7 (11.0.25)
@@ -1655,8 +1655,8 @@ CVE-2026-65637 (Improper Input Validation vulnerability in Apache Tomcat due to
 CVE-2026-65367 (A null pointer dereference was addressed with improved input validatio ...)
 	NOT-FOR-US: Apple
 CVE-2026-65183 (Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apa ...)
-	- tomcat11 <unfixed>
-	- tomcat10 <unfixed>
+	- tomcat11 <unfixed> (bug #1145698)
+	- tomcat10 <unfixed> (bug #1145699)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/4fb4523d70258614a00e7501ae0fdf3cdcbc2470 (11.0.25)
@@ -1664,8 +1664,8 @@ CVE-2026-65183 (Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
 	NOTE: https://github.com/apache/tomcat/commit/0206022f3aae65c5e0f23334b080849fdaaef444 (9.0.121)
 	NOTE: https://github.com/apache/tomcat/commit/07e1b7d3da47a97d2861116f0ba5dd2b4018d256 (9.0.121)
 CVE-2026-65182 (Improper Access Control, Incorrect Authorization vulnerability in Apac ...)
-	- tomcat11 <unfixed>
-	- tomcat10 <unfixed>
+	- tomcat11 <unfixed> (bug #1145698)
+	- tomcat10 <unfixed> (bug #1145699)
 	- tomcat9 9.0.70-2
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/8bafd79a3b54684e80e9cb1bafd4746aede7d3f5 (11.0.25)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4f87f935d5a117d779efe4cf26781ea8541272b9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4f87f935d5a117d779efe4cf26781ea8541272b9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/fb1ccc14/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list