Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package tomcat11 for openSUSE:Factory 
checked in at 2026-09-28 10:42:38
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/tomcat11 (Old)
 and      /work/SRC/openSUSE:Factory/.tomcat11.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "tomcat11"

Mon Sep 28 10:42:38 2026 rev:17 rq:1380699 version:11.0.26

Changes:
--------
--- /work/SRC/openSUSE:Factory/tomcat11/tomcat11.changes        2026-09-11 
18:07:38.893697619 +0200
+++ /work/SRC/openSUSE:Factory/.tomcat11.new.383539/tomcat11.changes    
2026-09-28 10:42:51.422915189 +0200
@@ -1,0 +2,169 @@
+Fri Sep 25 12:09:15 UTC 2026 - mbussolotto <[email protected]>
+
+- Update to Tomcat 11.0.26
+  * Fixed CVEs:
+    + CVE-2026-87022: Improper handling of length parameter allows WebSocket
+      message smuggling when per-message-deflate is used. (bsc#1282581)
+    + CVE-2026-86350: Inconsistent interpretation of HTTP/2 requests caused by
+      a regression in fix for CVE-2026-41293 can trigger request header mix-
+      up.
+    + CVE-2026-86248: CLIENT_CERT authentication does not fail as expected for
+      some scenarios when OCSP soft fail is disabled. (bsc#1282620)
+    + CVE-2026-79677: Due to a concurrency bug, an attacker could trigger a
+      denial of service as a result of lost time outs for asynchronous
+      WebSocket writes. (bsc#1282624)
+    + CVE-2026-78437: A malformed HTTP/2 request could potentially (depends on
+      timing) cause one request from another user to fail. (bsc#1282625)
+    + CVE-2026-78383: If the end user did not provide a request body, that
+      could pin an AJP processing thread leading to denial of service.
+      (bsc#1282626)
+    + CVE-2026-77791: A busy wait during sending of WebSocket close message
+      enabled a DoS attack. (bsc#1282627)
+    + CVE-2026-77762: A race condition allowed an attacker to inject trailer
+      fields into another HTTP/2 request. (bsc#1282599)
+    + CVE-2026-77756: Processing the transfer-encoding header for an HTTP/1.0
+      request may allow an attacker to cause one request from another user to
+      fail when Tomcat is located behind a reverse proxy. (bsc#1282628)
+    + CVE-2026-76183: Request paths were incorrectly parsed as endpoint
+      templates allowing the bypass of security constraints for WebSocket
+      endpoints. (bsc#1282629)
+    + CVE-2026-75973: When Jakarta Authentication was configured with
+      SimpleAuthConfigProvider as the default provider and multiple web
+      application used that provider, the realm for the first web application
+      to authenticate a request would be used for all web applications.
+      (bsc#1282630)
+    + CVE-2026-73581: Both the OpenSSL and OpenSSL-FFM TLS implementations
+      ignored CRLs when certificate used a keystore. (bsc#1282631)
+  * Catalina
+    + Fix: Improve the handling of AsyncContext.dispatch() when the Context
+      attribute dispatchersUseEncodedPaths is set to false since the
+      application has no control over the path used for the
+      AsyncContext.dispatch(). Prior to this fix, paths containing literal '?'
+      characters were truncated. (markt)
+    + Fix: Ensure that capture groups from a RewriteCond always reflect the
+      result of the current request. (markt)
+    + Fix: When a PersistentManager needs to reduce the number of active
+      sessions, swap out the least recently used eligible sessions first. Pull
+      request #1045 provided by sainadh777. (markt)
+    + Fix: Align web.xml logging output with the new Context attribute
+      urlPatternsProvidedInDecodedForm. (markt)
+    + Fix: Improve robustness of DIGEST authentication to system clock jumps.
+      (markt)
+    + Add: Support multiple protocol header values (treat as a single merged
+      header value) in the RemoteIpFilter and RemoteIpValve. (markt)
+    + Fix: potential concurrency issues when loading/saving sessions from/to a
+      session store. Custom Store implementations that do not extend StoreBase
+      must implement the new getSessionStoreLock() method of the Store
+      interface to ensure concurrency protection. The default method
+      implementation provided only provides the pre-fix functionality. (markt)
+    + Fix: Ensure that PersistentManager implementations that extend
+      PersistentManagerBase do not swap out sessions that are associated with
+      a request that is currently being processed. This includes not swapping
+      out a session unless the session was created when activity tracking was
+      enabled. (markt)
+    + Fix: Ensure namespace attributes are XML escaped in WebDAV responses.
+      (markt)
+    + Fix: Resolve null or missing rewrite substitutions as an empty string,
+      to align with the mod_rewrite behavior. (remm)
+    + Add: a best efforts protection in the CrawlerSessionManagerValve against
+      crawlers being associated with an authenticated session. (markt)
+    + Fix: Clarify the meaning of various RewriteValve server variables and
+      explicitly use the canonical context path for the CONTEXT_PATH server
+      variable. (markt)
+    + Fix: storeconfig not saving the path when a context is saved in
+      server.xml. (remm)
+    + Fix: WAR URLConnection should propagate use of caching. (remm)
+    + Fix: Ensure resources are evicted from the static resource cache in the
+      correct order. (markt)
+    + Fix: When Jakarta Authentication is configured for a web application,
+      cache the ServerAuthConfig in the Authenticator valve. This ensures web
+      application specific settings are cached on a per web application basis.
+      (markt)
+    + Fix: 70203: Fix RegistrationListener notifications in Jakarta
+      Authentication implementation. (markt)
+    + Fix: Handle CGI scripts that write excessively to stdout after setting
+      an HTTP error status code. (schultz)
+    + Fix: Require the request to the login action during FORM authentication
+      to be made using HTTP POST. (markt)
+    + Fix: 70208: Make URL encoding more robust. Based on pull request #1065
+      by Chenjp. (markt)
+  * Coyote
+    + Fix: parsing of client certificates that specify more than one OCSP
+      responder for configurations that use OpenSSL-FFM. (markt)
+    + Fix: xreflection generated code stack overflow issue. (remm)
+    + Fix: Align xreflection better with IntrospectionUtils. (remm)
+    + Fix: In HTTP/2 after half closed (remote), any unexpected frame should
+      be a stream error. (remm)
+    + Fix: incorrect initial window size calculation when upgrading to HTTP/2.
+      (remm)
+    + Fix: Avoid HTTP/2 exceptions with invalid content-length values. (remm)
+    + Fix: Only try and load the native library from the CATALINA_HOME system
+      property when the property is set. (markt)
+    + Fix: max connections enforcement after an enpoint resume. (remm)
+    + Fix: Implement stricter ALPN matching for Connectors using FFM. (markt)
+    + Add: length validation for ALPN protocol names. (markt)
+    + Fix: Make FFM certificate verification more robust. (markt)
+    + Fix: Align FFM OCSP URL parsing with Tomcat Native and treat a parsing
+      failure as if no usable OCSP URLs were present. (markt)
+    + Fix: Make the processing of OCSP responses more robust. (markt)
+    + Fix: Stricter OCSP handling when soft-fail is disabled. (markt)
+    + Fix: Cleaner handling of AJP response headers which overflow the maximum
+      message size. (remm)
+    + Fix: Small per performance optimisation. Don't waste cycles swallowing
+      an AJP response body when the connection is going to be closed. (markt)
+    + Fix: OpenSSL support for CRLs when using OpenSSL trust with the server
+      key held in a Java key store. (markt)
+    + Fix: Reject HTTP/1.0 or earlier requests that send a transfer-encoding
+      header. (markt)
+    + Fix: Ensure per request HTTP/2 bad request marker is cleared when the
+      request is recycled. (markt)
+    + Fix: Additional clean-up after HTTP/2 stream reset to aid GC. (markt)
+    + Fix: Revert earlier refactoring of HTTP/2 header field validation that
+      moved it earlier since the refactoring made correct handling of invalid
+      headers more difficult. (markt)
+  * Jasper
+    + Fix: EL evaluation of some lambda expressions. (remm)
+  * WebSocket
+    + Fix: an exception when an automatic Pong response races with the closing
+      of the WebSocket session. (moritzfl)
+    + Fix: Harden the WebSocket client and use a SecureRandom when generating
+      the Sec-WebSocket-Key header. (markt)
+    + Fix: Improve robustness of client handshakes. (remm)
+    + Fix: Ensure that WebSocket write timeouts apply to the complete message
+      and are not lost if two writes have the same timeout. (markt)
+    + Fix: Reduce CPU usage while sending WebSocket close message. (markt)
+    + Fix: overly broad check that prevented request URIs containing literal {
+      and } characters from being mapped to WebSocket end points. (markt)
+    + Fix: handling of WebSocket messages with compressed payloads using per-
+      message-deflate that have one or more non-final blocks where the BFINAL
+      bit is set. (markt)
+    + Fix: handling of per-message-deflate context takeover when receiving
+      compressed WebSocket messages. (markt)
+  * Web applications
+    + Fix: Manager: Fix a potential concurrency issue when ordering sessions
+      prior to displaying a list of session. (markt)
+    + Docs: Wrap the RewriteRule regular expression syntax reference on narrow
+      displays. Pull request #1044 by sainadh777. (markt)
+  * Other
+    + Update: Easymock to 5.7.0. (markt)
+    + Update: bnd to 7.4.0. (markt)
+    + Update: Tomcat Native to 2.0.16. (markt)
+    + Add: Improvements to French translations. (remm)
+    + Add: Improvements to Japanese translations provided by tak7iji and
+      Ktamura.biz.80. (markt)
+  * Cluster
+    + Fix: Validate that the DeltaManager attribute sendAllSessionsSize is a
+      positive integer. Zero or negative values previously caused an infinite
+      loop or a NegativeArraySizeException during session state transfer. Pull
+      request #1042 provided by lihongyi87. (markt)
+    + Fix: Improve robustness of cloud membership providers if an error occurs
+      fetching members. (remm)
+  * jdbc-pool
+    + Fix: DataSourceProxy.getPooledConnection(String,String) now delegates to
+      getConnection(String,String) rather than getConnection(). (markt)
+    + Add: Log a warning if an attempt is made to obtain a connection with
+      credentials when alternateUsernameAllowed is set to false. (markt)
+    + Fix: Ensure StatementCache interceptor resets properties of cached
+      statements between uses. (mark)
+
+-------------------------------------------------------------------

Old:
----
  apache-tomcat-11.0.25-src.tar.gz
  apache-tomcat-11.0.25-src.tar.gz.asc

New:
----
  apache-tomcat-11.0.26-src.tar.gz
  apache-tomcat-11.0.26-src.tar.gz.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ tomcat11.spec ++++++
--- /var/tmp/diff_new_pack.roydMN/_old  2026-09-28 10:42:52.397956021 +0200
+++ /var/tmp/diff_new_pack.roydMN/_new  2026-09-28 10:42:52.399956105 +0200
@@ -1,7 +1,7 @@
 #
 # spec file for package tomcat11
 #
-# Copyright (c) 2025-2026 SUSE LLC and contributors
+# Copyright (c) 2026 SUSE LLC and contributors
 # Copyright (c) 2000-2009, JPackage Project
 #
 # All modifications and additions to the file contributed by third parties
@@ -29,7 +29,7 @@
 %define elspec %{elspec_major}.%{elspec_minor}
 %define major_version 11
 %define minor_version 0
-%define micro_version 25
+%define micro_version 26
 %define java_major 1
 %define java_minor 17
 %define java_version %{java_major}.%{java_minor}

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.roydMN/_old  2026-09-28 10:42:52.452958324 +0200
+++ /var/tmp/diff_new_pack.roydMN/_new  2026-09-28 10:42:52.455958450 +0200
@@ -1,6 +1,6 @@
-mtime: 1788788318
-commit: 73c26622e3db2b2e95351421a690ead79c5777aafe85eb6ecd793ded2fd056d9
+mtime: 1790347203
+commit: 0947860e086425e76289bd997fa8040af10ee44501c1c129ae5a724db1584530
 url: https://src.opensuse.org/java-packages/tomcat11
-revision: 73c26622e3db2b2e95351421a690ead79c5777aafe85eb6ecd793ded2fd056d9
+revision: 0947860e086425e76289bd997fa8040af10ee44501c1c129ae5a724db1584530
 projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
 

++++++ apache-tomcat-11.0.25-src.tar.gz -> apache-tomcat-11.0.26-src.tar.gz 
++++++
/work/SRC/openSUSE:Factory/tomcat11/apache-tomcat-11.0.25-src.tar.gz 
/work/SRC/openSUSE:Factory/.tomcat11.new.383539/apache-tomcat-11.0.26-src.tar.gz
 differ: char 13, line 1

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-25 16:40:03.000000000 +0200
@@ -0,0 +1 @@
+.osc

Reply via email to