Bug#1142454: tomcat11: CVE-2026-59083 CVE-2026-59084
Salvatore Bonaccorso
carnil at debian.org
Mon Jul 20 09:07:50 BST 2026
Source: tomcat11
Version: 11.0.22-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerabilities were published for tomcat11.
CVE-2026-59083[0]:
| Improper Handling of URL Encoding (Hex Encoding) vulnerability in
| Apache Tomcat's rewrite valve allowed security constraint bypass for
| some configurations. This issue affects Apache Tomcat: from
| 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from
| 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions
| that have reached end of support may also be affected. Users are
| recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which
| fix the issue.
CVE-2026-59084[1]:
| Insufficient Technical Documentation vulnerability in Apache Tomcat
| since the requirements to securely configure the EncryptInterceptor
| were not clearly documented. This issue affects Apache Tomcat: from
| 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from
| 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100
| through 7.0.109. Other versions that have reached end of support may
| also be affected. Users are recommended to upgrade to version
| 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-59083
https://www.cve.org/CVERecord?id=CVE-2026-59083
[1] https://security-tracker.debian.org/tracker/CVE-2026-59084
https://www.cve.org/CVERecord?id=CVE-2026-59084
Regards,
Salvatore
More information about the pkg-java-maintainers
mailing list