Source: tomcat11 Version: 11.0.22-1 Severity: grave Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for tomcat11. CVE-2026-59083[0]: | Improper Handling of URL Encoding (Hex Encoding) vulnerability in | Apache Tomcat's rewrite valve allowed security constraint bypass for | some configurations. This issue affects Apache Tomcat: from | 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from | 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions | that have reached end of support may also be affected. Users are | recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which | fix the issue. CVE-2026-59084[1]: | Insufficient Technical Documentation vulnerability in Apache Tomcat | since the requirements to securely configure the EncryptInterceptor | were not clearly documented. This issue affects Apache Tomcat: from | 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from | 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 | through 7.0.109. Other versions that have reached end of support may | also be affected. Users are recommended to upgrade to version | 11.0.24, 10.1.57 or 9.0.120 which fix the issue. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-59083 https://www.cve.org/CVERecord?id=CVE-2026-59083 [1] https://security-tracker.debian.org/tracker/CVE-2026-59084 https://www.cve.org/CVERecord?id=CVE-2026-59084 Regards, Salvatore

