[Git][security-tracker-team/security-tracker][master] Track fixed version for tomcat10 issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Sep 20 09:18:59 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2bfbbadf by Salvatore Bonaccorso at 2026-09-20T10:18:29+02:00
Track fixed version for tomcat10 issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -33350,7 +33350,7 @@ CVE-2026-73335 (Android application "Myna Point" is vulnerable to Improper Autho
NOT-FOR-US: Myna Point
CVE-2026-73180 (Insufficient Session Expiration vulnerability in Apache Tomcat meant t ...)
- tomcat11 <unfixed> (bug #1145698)
- - tomcat10 <unfixed> (bug #1145699)
+ - tomcat10 10.1.60-1 (bug #1145699)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/e617a5d483b78851d289ca8dc1d68c49b541b419 (11.0.25)
@@ -33368,7 +33368,7 @@ CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect authentic
NOTE: Fixed by: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/commit/abb47dc5e6012ea05eda0b7979cc6bd41904011b (v1.10.4)
CVE-2026-68763 (Uncontrolled Resource Consumption vulnerability in Apache Tomcatvia an ...)
- tomcat11 <unfixed> (bug #1145698)
- - tomcat10 <unfixed> (bug #1145699)
+ - tomcat10 10.1.60-1 (bug #1145699)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/2a5ec806971627943db18601203129d9c58d959f (11.0.25)
@@ -33376,7 +33376,7 @@ CVE-2026-68763 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat
NOTE: https://github.com/apache/tomcat/commit/0747dd58cc631f90e044df246bd2ede6e2b48250 (9.0.121)
CVE-2026-68569 (Improper Authentication vulnerability in Apache Tomcat meant that in s ...)
- tomcat11 <unfixed> (bug #1145698)
- - tomcat10 <unfixed> (bug #1145699)
+ - tomcat10 10.1.60-1 (bug #1145699)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/790d6e2c3b4cd201a1fa556a23d5b7504dee18ad (11.0.25)
@@ -33384,7 +33384,7 @@ CVE-2026-68569 (Improper Authentication vulnerability in Apache Tomcat meant tha
NOTE: https://github.com/apache/tomcat/commit/8efd51f061c026f6339bfa4fe4ef919a04ef130a (9.0.121)
CVE-2026-68525 (Incorrect Authorization vulnerability in Apache Tomcat's FORM authenti ...)
- tomcat11 <unfixed> (bug #1145698)
- - tomcat10 <unfixed> (bug #1145699)
+ - tomcat10 10.1.60-1 (bug #1145699)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/10d048e16034ddf12055e0cede0da05b15c823b8 (11.0.25)
@@ -33416,7 +33416,7 @@ CVE-2026-68513 (OpenEXR is the reference implementation and specification for th
NOTE: Introduced by: https://github.com/AcademySoftwareFoundation/openexr/commit/84d7d52e17a17e18d138d9d1aa9f4e2de2fcb2d6 (v3.3.0-rc)
CVE-2026-66422 (Improper Authorization vulnerability in Apache Tomcat cause by securit ...)
- tomcat11 <unfixed> (bug #1145698)
- - tomcat10 <unfixed> (bug #1145699)
+ - tomcat10 10.1.60-1 (bug #1145699)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/2c2c510ab10ae7796de6c6f7b70abae85c99d30d (11.0.25)
@@ -33428,7 +33428,7 @@ CVE-2026-66152 (A Path traversal vulnerability in the SonicWall NetExtender Linu
NOT-FOR-US: SonicWall
CVE-2026-65927 (Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag ...)
- tomcat11 <unfixed> (bug #1145698)
- - tomcat10 <unfixed> (bug #1145699)
+ - tomcat10 10.1.60-1 (bug #1145699)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/bce83410ffb1542752d52b536257e81a5c8dfcb8 (11.0.25)
@@ -33439,7 +33439,7 @@ CVE-2026-65927 (Off-by-one Error vulnerability in Apache Tomcat impacting the [N
NOTE: https://github.com/apache/tomcat/commit/b477537e68acfcaa7220f90b512bf8a72bf237dc (9.0.121)
CVE-2026-65905 (Authentication Bypass by Capture-replay vulnerability in Apache Tomcat ...)
- tomcat11 <unfixed> (bug #1145698)
- - tomcat10 <unfixed> (bug #1145699)
+ - tomcat10 10.1.60-1 (bug #1145699)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/c5f94ad1726e8399b77eb3fd69c811c1103894d6 (11.0.25)
@@ -33447,7 +33447,7 @@ CVE-2026-65905 (Authentication Bypass by Capture-replay vulnerability in Apache
NOTE: https://github.com/apache/tomcat/commit/a31181af45e494b6035575519f6d1d33875f050d (9.0.121)
CVE-2026-65637 (Improper Input Validation vulnerability in Apache Tomcat due to incomp ...)
- tomcat11 <unfixed> (bug #1145698)
- - tomcat10 <unfixed> (bug #1145699)
+ - tomcat10 10.1.60-1 (bug #1145699)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/8639b20f045c88f356b887204f52e897399f0de7 (11.0.25)
@@ -33457,7 +33457,7 @@ CVE-2026-65367 (A null pointer dereference was addressed with improved input val
NOT-FOR-US: Apple
CVE-2026-65183 (Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apa ...)
- tomcat11 <unfixed> (bug #1145698)
- - tomcat10 <unfixed> (bug #1145699)
+ - tomcat10 10.1.60-1 (bug #1145699)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/4fb4523d70258614a00e7501ae0fdf3cdcbc2470 (11.0.25)
@@ -33466,7 +33466,7 @@ CVE-2026-65183 (Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
NOTE: https://github.com/apache/tomcat/commit/07e1b7d3da47a97d2861116f0ba5dd2b4018d256 (9.0.121)
CVE-2026-65182 (Improper Access Control, Incorrect Authorization vulnerability in Apac ...)
- tomcat11 <unfixed> (bug #1145698)
- - tomcat10 <unfixed> (bug #1145699)
+ - tomcat10 10.1.60-1 (bug #1145699)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/8bafd79a3b54684e80e9cb1bafd4746aede7d3f5 (11.0.25)
@@ -66611,7 +66611,7 @@ CVE-2026-66713 (Deserialization of Untrusted Data (CWE-502) in the Tribes-based
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66299 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat's Web ...)
- tomcat11 <unfixed> (unimportant)
- - tomcat10 <unfixed> (unimportant)
+ - tomcat10 10.1.60-1 (unimportant)
- tomcat9 9.0.70-2 (unimportant)
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://lists.apache.org/thread/8owczcc1o8qw1rxmg9gvfk4w2jnh4l5k
@@ -81159,7 +81159,7 @@ CVE-2026-59197 (Pillow is a Python imaging library. Prior to 12.3.0, Pillow's pu
NOTE: Fixed by: https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1 (12.3.0)
CVE-2026-59084 (Insufficient Technical Documentation vulnerability in Apache Tomcat si ...)
- tomcat11 11.0.24-1 (bug #1142454)
- - tomcat10 <unfixed> (bug #1142455)
+ - tomcat10 10.1.60-1 (bug #1142455)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/57e80e9b8bb7cb563929db47fd24fe787251f478 (11.0.24)
@@ -81167,7 +81167,7 @@ CVE-2026-59084 (Insufficient Technical Documentation vulnerability in Apache Tom
NOTE: https://github.com/apache/tomcat/commit/617d7275782bf58b45f6b7ea82c2edf16660e0b3 (9.0.120)
CVE-2026-59083 (Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apac ...)
- tomcat11 11.0.24-1 (bug #1142454)
- - tomcat10 <unfixed> (bug #1142455)
+ - tomcat10 10.1.60-1 (bug #1142455)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/f00ab28725a18c7fffda421e9858c27badcac1e4 (11.0.24)
@@ -93253,7 +93253,7 @@ CVE-2026-10647 (The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-55956 (Improper Authorization vulnerability in Apache Tomcat leads to securit ...)
- tomcat11 11.0.24-1 (bug #1141337)
- - tomcat10 <unfixed> (bug #1141338)
+ - tomcat10 10.1.60-1 (bug #1141338)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/3f6bd2ba5e53d1f340bbe5ad2d42a28b29440b7a (11.0.23)
@@ -93261,7 +93261,7 @@ CVE-2026-55956 (Improper Authorization vulnerability in Apache Tomcat leads to s
NOTE: https://github.com/apache/tomcat/commit/a0374c450970760efafbd8806a1db278830ba7bd (9.0.119)
CVE-2026-55955 (Improper Authentication vulnerability in Apache Tomcat allowed a repla ...)
- tomcat11 11.0.24-1 (bug #1141337)
- - tomcat10 <unfixed> (bug #1141338)
+ - tomcat10 10.1.60-1 (bug #1141338)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/5e594400c7f6ac0eaf2526bd64442a70f5ccaace (11.0.23)
@@ -93269,7 +93269,7 @@ CVE-2026-55955 (Improper Authentication vulnerability in Apache Tomcat allowed a
NOTE: https://github.com/apache/tomcat/commit/6a7a432cd7fb4ef358dc12e8da99cf3ab320f3fe (9.0.119)
CVE-2026-55276 (Always-Incorrect Control Flow Implementation vulnerability in Apache T ...)
- tomcat11 11.0.24-1 (bug #1141337)
- - tomcat10 <unfixed> (bug #1141338)
+ - tomcat10 10.1.60-1 (bug #1141338)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/f844614c6d92eeb11e81e179606bf4c390f642dd (11.0.23)
@@ -93279,7 +93279,7 @@ CVE-2026-55276 (Always-Incorrect Control Flow Implementation vulnerability in Ap
NOTE: https://github.com/apache/tomcat/commit/3ca8cae5fd3796b1bd9759e11b0e238161e7a39c (9.0.119)
CVE-2026-53434 (Detection of Error Condition Without Action vulnerability in Apache To ...)
- tomcat11 11.0.24-1 (bug #1141337)
- - tomcat10 <unfixed> (bug #1141338)
+ - tomcat10 10.1.60-1 (bug #1141338)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/7f8ecdbd930d8c5a7fae73aa0eec9124d919e2f5 (11.0.23)
@@ -93287,7 +93287,7 @@ CVE-2026-53434 (Detection of Error Condition Without Action vulnerability in Apa
NOTE: https://github.com/apache/tomcat/commit/c48ac39c27f4494f8c96b9d56a487253e362d276 (9.0.119)
CVE-2026-53404 (Always-Incorrect Control Flow Implementation vulnerability in Apache T ...)
- tomcat11 11.0.24-1 (bug #1141337)
- - tomcat10 <unfixed> (bug #1141338)
+ - tomcat10 10.1.60-1 (bug #1141338)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/b647cb584cea8bf95e64f5d2526c59ab8fca3225 (11.0.23)
@@ -93295,7 +93295,7 @@ CVE-2026-53404 (Always-Incorrect Control Flow Implementation vulnerability in Ap
NOTE: https://github.com/apache/tomcat/commit/fe06ae8a71997061596f54189dae1b1b5da75430 (9.0.119)
CVE-2026-50229 (Improper Neutralization of Script-Related HTML Tags in a Web Page (Bas ...)
- tomcat11 11.0.24-1 (bug #1141337)
- - tomcat10 <unfixed> (bug #1141338)
+ - tomcat10 10.1.60-1 (bug #1141338)
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
NOTE: https://github.com/apache/tomcat/commit/1fe95d841e9d461a16069974142d12c3ef68819a (11.0.23)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2bfbbadf809322073a418490e92f18cdc0266f73
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2bfbbadf809322073a418490e92f18cdc0266f73
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/ff9b48c3/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list