Source: tomcat11
Version: 11.0.22-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for tomcat11.

CVE-2026-59083[0]:
| Improper Handling of URL Encoding (Hex Encoding) vulnerability in
| Apache Tomcat's rewrite valve allowed security constraint bypass for
| some configurations.  This issue affects Apache Tomcat: from
| 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from
| 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions
| that have reached end of support may also be affected.  Users are
| recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which
| fix the issue.


CVE-2026-59084[1]:
| Insufficient Technical Documentation vulnerability in Apache Tomcat
| since the requirements to securely configure the EncryptInterceptor
| were not clearly documented.  This issue affects Apache Tomcat: from
| 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from
| 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100
| through 7.0.109. Other versions that have reached end of support may
| also be affected.  Users are recommended to upgrade to version
| 11.0.24, 10.1.57 or 9.0.120 which fix the issue.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-59083
    https://www.cve.org/CVERecord?id=CVE-2026-59083
[1] https://security-tracker.debian.org/tracker/CVE-2026-59084
    https://www.cve.org/CVERecord?id=CVE-2026-59084

Regards,
Salvatore

Reply via email to