[Git][security-tracker-team/security-tracker][master] Add CVE-2026-66299/tomcat

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 05:17:06 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
816fda27 by Salvatore Bonaccorso at 2026-07-29T06:16:37+02:00
Add CVE-2026-66299/tomcat

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -75,7 +75,12 @@ CVE-2026-66745 (Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix
 CVE-2026-66713 (Deserialization of Untrusted Data (CWE-502) in the Tribes-based cluste ...)
 	TODO: check
 CVE-2026-66299 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat's Web ...)
-	TODO: check
+	- tomcat11 <unfixed> (unimportant)
+	- tomcat10 <unfixed> (unimportant)
+	- tomcat9 9.0.70-2 (unimportant)
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
+	NOTE: https://lists.apache.org/thread/8owczcc1o8qw1rxmg9gvfk4w2jnh4l5k
+	NOTE: Only affects the WebSocket chat example
 CVE-2026-65882 (Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdl ...)
 	NOT-FOR-US: Joomla
 CVE-2026-65881 (Joomla Extension - joomdle.com - Insecure default configuration allows ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/816fda272efef9b3ff2d85fdc20049a6bb5f5c80

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/816fda272efef9b3ff2d85fdc20049a6bb5f5c80
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/9fbb5ef1/attachment.htm>


More information about the debian-security-tracker-commits mailing list