[Git][security-tracker-team/security-tracker][master] Add new tomcat9 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 23 21:14:45 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
35cff175 by Salvatore Bonaccorso at 2026-09-23T22:14:05+02:00
Add new tomcat9 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,63 +1,99 @@
 CVE-2026-87022
 	- tomcat11 <unfixed>
 	- tomcat10 10.1.60-1
+	- tomcat9 9.0.70-2
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/4fef25fe2ab7509e697af093280b9daadb515615 (11.0.26)
 	NOTE: https://github.com/apache/tomcat/commit/567a85515b78d1cd6410a89844b88109fcc2306f (10.1.60)
+	NOTE: https://github.com/apache/tomcat/commit/959a52a227cc35101b92dae35b722546167594d6 (9.0.122)
 CVE-2026-86350
 	- tomcat11 <unfixed>
 	- tomcat10 10.1.60-1
+	- tomcat9 9.0.70-2
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/192bc74996e1ad35d79118f750574d366bd43cea (11.0.26)
 	NOTE: https://github.com/apache/tomcat/commit/259e938d3dedf07f3b24189fd5032adb95b01f2a (10.1.60)
+	NOTE: https://github.com/apache/tomcat/commit/5adadc4ef413d5050f664d40800bbff74bd5d5ed (9.0.122)
 CVE-2026-86248
 	- tomcat11 <unfixed>
 	- tomcat10 10.1.60-1
+	- tomcat9 9.0.70-2
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/9aab76056e7470bcc8ca9a20b33b6558b1046da2 (11.0.26)
 	NOTE: https://github.com/apache/tomcat/commit/e5191b1e3292681097503f093b5432451ff5aa83 (10.1.60)
+	NOTE: https://github.com/apache/tomcat/commit/fc41d82e0e383e4d6e88ad321d245dafdc17d26d (9.0.122)
 CVE-2026-79677
 	- tomcat11 <unfixed>
 	- tomcat10 10.1.60-1
+	- tomcat9 9.0.70-2
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/7ab11d10de79a7a2226f41c8289871db69c6ca9c (11.0.26)
 	NOTE: https://github.com/apache/tomcat/commit/bb676e53cd0bdcbecfe9650841e99973a7693f7e (10.1.60)
+	NOTE: https://github.com/apache/tomcat/commit/c8fa5430233bca5b209c593dd446f88fda9d543e (9.0.122)
 CVE-2026-78437
 	- tomcat11 <unfixed>
 	- tomcat10 10.1.60-1
+	- tomcat9 9.0.70-2
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/70579060454a203977b5696ece71e7cbd6ee9bde (11.0.26)
 	NOTE: https://github.com/apache/tomcat/commit/4ac5da0906c500f6042844d7f17e9fb174820758 (10.1.60)
+	NOTE: https://github.com/apache/tomcat/commit/a28c35055ab11d35929ad564beb1a23a67b39546 (9.0.122)
 CVE-2026-78383
 	- tomcat11 <unfixed>
 	- tomcat10 10.1.60-1
+	- tomcat9 9.0.70-2
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/6dabd4303095785183ede57f6d162c542955a5a8 (11.0.26)
 	NOTE: https://github.com/apache/tomcat/commit/2ed6d18ebfe4b085ef050dd0a0f4f20aff3bc48d (10.1.60)
+	NOTE: https://github.com/apache/tomcat/commit/265bdc0a58b1447ff5d8f8b96ea81de58cb74c8c (9.0.122)
 CVE-2026-77791
 	- tomcat11 <unfixed>
 	- tomcat10 10.1.60-1
+	- tomcat9 9.0.70-2
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/ce291bbc65393e3bfbec2a8d23fcee0106a1ade9 (11.0.26)
 	NOTE: https://github.com/apache/tomcat/commit/e896f73c868f66dfb2a93565fda4d13cd5909d2d (10.1.60)
+	NOTE: https://github.com/apache/tomcat/commit/7a5945f1de1d3310214234dfbbd7c569af52d058 (9.0.122)
 CVE-2026-77762
 	- tomcat11 <unfixed>
 	- tomcat10 10.1.60-1
+	- tomcat9 9.0.70-2
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/fd309997dfd0d351b26959a8afd7bffec33dd0de (11.0.26)
 	NOTE: https://github.com/apache/tomcat/commit/77d2d59347891eced52b0cb5a979fc33a8a2620c (10.1.60)
+	NOTE: https://github.com/apache/tomcat/commit/71f27c2e84810930beda468b5ba732dcd0ef2652 (9.0.122)
 CVE-2026-77756
 	- tomcat11 <unfixed>
 	- tomcat10 10.1.60-1
+	- tomcat9 9.0.70-2
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/1ad63de866a6e7007304ebe5165f72e65ece32b6 (11.0.26)
 	NOTE: https://github.com/apache/tomcat/commit/bf44bee23d97fbb1a64cbbbb213ff2b6506d26c4 (10.1.60)
+	NOTE: https://github.com/apache/tomcat/commit/e590588ab7649c93d49b0eb7b3152700a977880d (9.0.122)
 CVE-2026-76183
 	- tomcat11 <unfixed>
 	- tomcat10 10.1.60-1
+	- tomcat9 9.0.70-2
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/e182d86b7d4cc19ec4c24c38f37acc004404fe8e (11.0.26)
 	NOTE: https://github.com/apache/tomcat/commit/5b48790abd13d94c2bd351027a39a671916b5ddf (10.1.60)
+	NOTE: https://github.com/apache/tomcat/commit/a93a60a33f4cc202542eb6a0b87b7142d7db311c (9.0.122)
 CVE-2026-75973
 	- tomcat11 <unfixed>
 	- tomcat10 10.1.60-1
+	- tomcat9 9.0.70-2
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/2585fc798f24f0b8811fd20ad9b4e8affb6f69a6 (11.0.26)
 	NOTE: https://github.com/apache/tomcat/commit/f62c65768fdaa300e22e64ffa7b5118dce0571a1 (10.1.60)
+	NOTE: https://github.com/apache/tomcat/commit/043115414a39127cad015e9d285296e59c18bb41 (9.0.122)
 CVE-2026-73581
 	- tomcat11 <unfixed>
 	- tomcat10 10.1.60-1
+	- tomcat9 9.0.70-2
+	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://github.com/apache/tomcat/commit/15a76156ced9f6a6306ef7d6f2e343034231a2de (11.0.26)
 	NOTE: https://github.com/apache/tomcat/commit/6907d47ea2d4c3f13ef9f65b0c51ff2fd485c252 (10.1.60)
+	NOTE: https://github.com/apache/tomcat/commit/2dce8f26b3ba6a89c8f172b94fa41a5fa2dcc361 (9.0.122)
 CVE-2026-XXXX [GHSA-pc48-m7cx-qf72: NTFS-3G-SA_2026-06-1_20]
 	[experimental] - ntfs-3g 1:2026.9.18-1
 	- ntfs-3g <unfixed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/35cff175e1aed89e479f0158be5b4547a29aa309

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/35cff175e1aed89e479f0158be5b4547a29aa309
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/2cb48deb/attachment.htm>


More information about the debian-security-tracker-commits mailing list