Messages by Thread
-
OT: Entra ID Realm for Tomcat
Zoran Avtarovski
-
Tomcat website, RSS and social media
Thorsten Heit
-
Log headers for failing request
Harri Pesonen via users
-
[ANN] Apache Tomcat Migration tool for Jakarta EE 1.0.12
Mark Thomas
-
Is Tomcat affected by CVE-2026-49975 (HTTP/2 Bomb)?
Stefan Mayr
-
Logging of which jars did or didn't need scanning?
Holle, Jess via users
-
Informal poll of Tomcat version usage
Christopher Schultz
-
[BUG] Parameters.recycle() does not reset queryStringCharset — leaks across recycled Requests
황인엽
-
Fwd: Questions regarding updating Apache Tomcat on a server.
Brian Proffitt
-
Fw: Tomcat Jobs
Jon McAlexander
-
[SECURITY] CVE-2026-43515 Apache Tomcat - Security constraints not correctly applied
Mark Thomas
-
[SECURITY] CVE-2026-43514 Apache Tomcat - AJP secret compared in non-constant time
Mark Thomas
-
[SECURITY] CVE-2026-43513 Apache Tomcat - LockOutRealm treats user names as case-sensitive
Mark Thomas
-
[SECURITY] CVE-2026-43512 Apache Tomcat - Digest authenticator will authenticate any unknown user
Mark Thomas
-
[SECURITY] CVE-2026-42498 Apache Tomcat - WebSocket authentication header exposure
Mark Thomas
-
[SECURITY] CVE-2026-41293 Apache Tomcat - HTTP/2 request headers not validated
Mark Thomas
-
[SECURITY] CVE-2026-41284 Apache Tomcat - Unbounded read in WebDAV LOCK and PROPFIND handling
Mark Thomas
-
[ANN] Apache Tomcat 10.1.55 Available
Christopher Schultz
-
[ANN] Apache Tomcat 9.0.118 available
Rémy Maucherat
-
[ANN] Apache Tomcat 11.0.22 Available
Mark Thomas
-
Very rare requests claim they are from 127.0.0.1
Christopher Schultz
-
Community Over Code Conference, October 2026, Glasgow, Scotland, UK
Christopher Schultz
-
Clarification on Tomcat 9.1 Release Timeline and Support Plans
somasani nikhil
-
Limits on redirect length
Stephen Booth
-
Double Slash Conversion to Single Slash in URL Not Working
Grackin, Michael A. Mr. (Fed) via users
-
cgi not found
Holger Klawitter
-
[SECURITY] CVE-2026-34487 Apache Tomcat - Cloud membership for clustering component exposed the Kubernetes bearer token
Mark Thomas
-
[SECURITY] CVE-2026-34486 Apache Tomcat - Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Mark Thomas
-
[SECURITY] CVE-2026-34500 Apache Tomcat - OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas
-
[SECURITY] CVE-2026-34483 Apache Tomcat - Incomplete escaping of JSON access logs
Mark Thomas
-
[SECURITY] CVE-2026-32990 Apache Tomcat - The fix for CVE-2025-66614 is incomplete
Mark Thomas
-
[SECURITY] CVE-2026-29146 Apache Tomcat - EncryptInterceptor vulnerable to padding oracle attack by default
Mark Thomas
-
[SECURITY] CVE-2026-29145 Apache Tomcat and Tomcat Native - OCSP checks sometimes soft-fail even when soft-fail is disabled
Mark Thomas
-
[SECURITY] CVE-2026-29129 Apache Tomcat - Configured TLS cipher preference order not preserved
Mark Thomas
-
[SECURITY] CVE-2026-25854 Apache Tomcat - Occasionally open redirect
Mark Thomas
-
[SECURITY] CVE-2026-24880 Apache Tomcat - Request smuggling via invalid chunk extension
Mark Thomas
-
[ANN] Apache Tomcat 11.0.21 Available
Mark Thomas
-
[ANN] Apache Tomcat 9.0.117 available
Rémy Maucherat
-
[ANN] Apache Tomcat 10.1.54 Available
Christopher Schultz
-
[ANN] End Of Support for Tomcat Native 1.x
Christopher Schultz
-
Tomcat 9.0.37 - Request Header Parsing Exception: X-Forwarded-For Lost and Host Field Duplicated Resulting in 400 Bad Request
扛起一片天!✨
-
Tomcat 11.0.18 - java.lang.AssertionError in Mapper#internalMap
Torsten Krah
-
[ANN] Apache Tomcat 10.1.53 Available
Christopher Schultz
-
[ANN] Apache Tomcat 9.0.116 available
Rémy Maucherat
-
[ANN] Apache Tomcat 11.0.20 Available
Mark Thomas
-
Apache Tomcat 9.0.108 -- Upgrading to 9.1.x and Release Info
Jack Haddad
-
Tomcat 11 latest release version date
Deepti Sharma S via users
-
FIPS Mode
Mike Brown
-
Run Priority -- Tomcat running on IBM Midrange boxes
James H. H. Lampert via users
-
[ANN] Apache Tomcat Native 2.0.14 released
Mark Thomas
-
[ANN] Apache Tomcat Native 1.3.7 released
Mark Thomas
-
Recall: Apache Tomcat 10 Issue
Mcalexander, Jon J. via users
-
Re: users Digest 6 Mar 2026 16:12:31 -0000 Issue 15160
Richard Huntrods
-
Apache Tomcat 10 Issue
Short, William J.
-
Access log Bytes Written when compression is enabled
David Cleary
-
Order of ciphers is no longer preserved
Benny Prange
-
[SECURITY] CVE-2026-24733 Apache Tomcat - Security constraint bypass with HTTP/0.9
Mark Thomas
-
[SECURITY] CVE-2026-24734 Apache Tomcat and Tomcat Native - OCSP revocation bypass
Mark Thomas
-
[SECURITY] CVE-2025-66614 Apache Tomcat - Client certificate verification bypass due to virtual host mapping
Mark Thomas
-
Ignored JSSE properties in Tomcat 11.0.12+ and Java21+
Benny Prange
-
[ANN] End of support for Apache Tomcat Native 1.3.x
Mark Thomas
-
[ANN] Tomcat 9.0.x End of Support and Tomcat 9 long term support plan
Mark Thomas
-
[ANN] Apache Tomcat Native 1.3.6 released
Mark Thomas
-
[ANN] Apache Tomcat Native 2.0.13 released
Mark Thomas
-
[Inquiry] java.lang.IllegalStateException: setAttribute: Session already invalidated during Cluster Replication (Tomcat 9.0.73)
조재현
-
Set "X-Frame-Options" SAMEORIGIN to ALWAYS ?
Baron Fujimoto
-
NoClassDefFoundError of OSGI class SynchronousBundleListener for Tyrus initialization
Robert von Burg
-
Re: Apache Tomcat Server (V 10.1.50) / Cybersecurity risk assessment
Christopher Schultz
-
Tomcat config with virtual threads
joan.balaguero
-
[ANN] Apache Tomcat 11.0.18 Available
Mark Thomas
-
move to tomcat 11, now see a jasper dependency
Rob Sargent