[ 
https://issues.apache.org/jira/browse/TOMEE-4677?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18109831#comment-18109831
 ] 

RAJU THANNEERU edited comment on TOMEE-4677 at 8/31/26 9:51 AM:
----------------------------------------------------------------

Hi [~jungm], we see multiple criticals and highs in tomcat.
Here is the PR link, hope you can check and merge it.
[https://github.com/apache/tomee/pull/2906]
|[CVE-2026-65182|https://nvd.nist.gov/vuln/detail/CVE-2026-65182]|9.1|critical|fixed
 in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-65637|https://nvd.nist.gov/vuln/detail/CVE-2026-65637]|9.8|critical|fixed
 in 11.0.25, 10.1.58, 9.0.121|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-65905|https://nvd.nist.gov/vuln/detail/CVE-2026-65905]|9.8|critical|fixed
 in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-68525|https://nvd.nist.gov/vuln/detail/CVE-2026-68525]|9.1|critical|fixed
 in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-65183|https://nvd.nist.gov/vuln/detail/CVE-2026-65183]|8.1|high|fixed
 in 11.0.25, 10.1.58, 9.0.121|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-65927|https://nvd.nist.gov/vuln/detail/CVE-2026-65927]|7.5|high|fixed
 in 11.0.25, 10.1.58, 9.0.121|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-66422|https://nvd.nist.gov/vuln/detail/CVE-2026-66422]|8.1|high|fixed
 in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-68569|https://nvd.nist.gov/vuln/detail/CVE-2026-68569]|8.1|high|fixed
 in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-68763|https://nvd.nist.gov/vuln/detail/CVE-2026-68763]|7.5|high|fixed
 in 11.0.25, 10.1.58, 9.0.121|2026-08-27 17:28:44 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-66299|https://nvd.nist.gov/vuln/detail/CVE-2026-66299]|5.3|medium|fixed
 in 11.0.25, 10.1.58, 9.0.121|2026-08-06 09:29:28 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-73180|https://nvd.nist.gov/vuln/detail/CVE-2026-73180]|6.8|medium|fixed
 in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 17:28:44 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|


was (Author: JIRAUSER296575):
[HiĀ |https://github.com/apache/tomee/pull/2906] [Markus 
Jung|https://github.com/apache/tomee/pull/2906], we see multiple criticals and 
highs in tomcat.
Here is the PR link, hope you can check and merge it.
[https://github.com/apache/tomee/pull/2906]


|[CVE-2026-65182|https://nvd.nist.gov/vuln/detail/CVE-2026-65182]|9.1|critical|fixed
 in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-65637|https://nvd.nist.gov/vuln/detail/CVE-2026-65637]|9.8|critical|fixed
 in 11.0.25, 10.1.58, 9.0.121|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-65905|https://nvd.nist.gov/vuln/detail/CVE-2026-65905]|9.8|critical|fixed
 in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-68525|https://nvd.nist.gov/vuln/detail/CVE-2026-68525]|9.1|critical|fixed
 in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-65183|https://nvd.nist.gov/vuln/detail/CVE-2026-65183]|8.1|high|fixed
 in 11.0.25, 10.1.58, 9.0.121|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-65927|https://nvd.nist.gov/vuln/detail/CVE-2026-65927]|7.5|high|fixed
 in 11.0.25, 10.1.58, 9.0.121|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-66422|https://nvd.nist.gov/vuln/detail/CVE-2026-66422]|8.1|high|fixed
 in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-68569|https://nvd.nist.gov/vuln/detail/CVE-2026-68569]|8.1|high|fixed
 in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-68763|https://nvd.nist.gov/vuln/detail/CVE-2026-68763]|7.5|high|fixed
 in 11.0.25, 10.1.58, 9.0.121|2026-08-27 17:28:44 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-66299|https://nvd.nist.gov/vuln/detail/CVE-2026-66299]|5.3|medium|fixed
 in 11.0.25, 10.1.58, 9.0.121|2026-08-06 09:29:28 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-73180|https://nvd.nist.gov/vuln/detail/CVE-2026-73180]|6.8|medium|fixed
 in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 17:28:44 +0000 
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
 image|/usr/local/tomee/lib/tomcat-util.jar|

> Upgrade tomcat to 10.1.59
> -------------------------
>
>                 Key: TOMEE-4677
>                 URL: https://issues.apache.org/jira/browse/TOMEE-4677
>             Project: TomEE
>          Issue Type: Dependency upgrade
>          Components: TomEE Core Server
>    Affects Versions: 10.2.0
>            Reporter: RAJU THANNEERU
>            Priority: Major
>             Fix For: 10.3.0
>
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> |[CVE-2026-66299|https://nvd.nist.gov/vuln/detail/CVE-2026-66299]|7.5|high|fixed
>  in 11.0.25, 10.1.58, 9.0.121|2026-08-06 09:29:28 +0000 
> UTC|[tomcat-util_10.1.57|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_tomcat-util_10.1.57]|this
>  image|/usr/local/tomee/lib/tomcat-util.jar|



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to