users
Thread
Date
Earlier messages
Messages by Thread
Fwd: Version 10.1.57 / 10.1.59
Brian Proffitt
AW: Version 10.1.57 / 10.1.59
Thomas Hoffmann (Speed4Trade GmbH) via users
Re: AW: Version 10.1.57 / 10.1.59
Mark Thomas
Update for new versions
Venkumahanti Praveen
Re: Update for new versions
Mark Thomas
Tomcat Embed Core 10.1.58
Raghu Dev
Re: Tomcat Embed Core 10.1.58
Chuck Caldarale
Re: Tomcat Embed Core 10.1.58
Eric Fetzer
Re: Tomcat Embed Core 10.1.58
Mark Thomas
Re: Tomcat Embed Core 10.1.58
Eric Fetzer
[ANN] Apache Tomcat 9.0.121 available
Rémy Maucherat
[ANN] Apache Tomcat 11.0.25 Available
Mark Thomas
Status and timeline inquiry for Apache Tomcat 11.0.25 release
Terry ST SY/DPO
Re: Status and timeline inquiry for Apache Tomcat 11.0.25 release
Chuck Caldarale
Tomcat 11.0.25 Release Timeline Inquiry
joao-paulo.martins-prestataire.ca-ps.com via users
Re: Tomcat 11.0.25 Release Timeline Inquiry
Sebastian Trost via users
Re: Tomcat 11.0.25 Release Timeline Inquiry
Jo�o Paulo Sim�es Martins via users
Re: Tomcat 11.0.25 Release Timeline Inquiry
Mark Thomas
Re: Tomcat 11.0.25 Release Timeline Inquiry
Christopher Schultz
Session clustering between tomcat versions.
Stephen Booth
Re: Session clustering between tomcat versions.
Mark Thomas
Regarding apache-tomcat 10.1.58 version
Roshan Patil
AW: Regarding apache-tomcat 10.1.58 version
Döscher, Andreas (ESI) via users
Re: AW: Regarding apache-tomcat 10.1.58 version
Roshan Patil
Re: Regarding apache-tomcat 10.1.58 version
Rob Sargent
Re: AW: Regarding apache-tomcat 10.1.58 version
Mark Thomas
Regarding apache-tomcat 10.1.58 version
Roshan Patil
Re: Regarding apache-tomcat 10.1.58 version
Mark Thomas
Community over Code Sydney 2026
Mark Thomas
Re: Community over Code Sydney 2026
Mark Thomas
Community over Code Glasgow 2026
Mark Thomas
[SECURITY] CVE-2026-66299 Apache Tomcat - DoS via WebSocket chat example
Mark Thomas
London - Tues 28 July - evening
Mark Thomas
Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
LAURIA Giuseppe via users
Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Tim Funk
AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
LAURIA Giuseppe via users
Re: AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Sebastian Trost via users
Re: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Peter Kreuser
Re: AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Mark Thomas
Re: AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Rémy Maucherat
AW: [EXTERNAL] Re: AW: Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
LAURIA Giuseppe via users
Re: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Zdeněk Henek
Re: AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Christopher Schultz
Tomcat Jobs?
Jon McAlexander
Re: Tomcat Jobs?
Sebastian Trost via users
Re: Tomcat Jobs?
Jon McAlexander
Re: Tomcat Jobs?
Sebastian Trost via users
Possible missing CVE commits in 9.0.120, 10.1.57 and 11.0.24 release builds
Thomas Williams
Re: Possible missing CVE commits in 9.0.120, 10.1.57 and 11.0.24 release builds
Mark Thomas
Apache Tomcat 9.1.x release timeframe
Lisa Sayre
Re: Apache Tomcat 9.1.x release timeframe
Mark Thomas
Re: Apache Tomcat 9.1.x release timeframe
david w
RE: Apache Tomcat 9.1.x release timeframe
Lisa Sayre
Re: Apache Tomcat 9.1.x release timeframe
Sebastian Trost via users
RE: Apache Tomcat 9.1.x release timeframe
Eddie Rowe via users
Re: Apache Tomcat 9.1.x release timeframe
Mark Thomas
RE: Apache Tomcat 9.1.x release timeframe
Lisa Sayre
Re: Apache Tomcat 9.1.x release timeframe
Mark Thomas
RE: Apache Tomcat 9.1.x release timeframe
Lisa Sayre
Re: Apache Tomcat 9.1.x release timeframe
Christopher Schultz
Re: Apache Tomcat 9.1.x release timeframe
Sebastian Trost via users
Re: [OT] Apache Tomcat 9.1.x release timeframe
Christopher Schultz
Re: Apache Tomcat 9.1.x release timeframe
Christopher Schultz
Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Olaf Kock
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
Christopher Schultz
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
GUSTAVO AVITABILE
Re: Tomcat host header redirect issue
GUSTAVO AVITABILE
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
Christopher Schultz
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Christopher Schultz
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
Johan Compagner
jspwiki-wiki down?!
Holger Klawitter
Re: jspwiki-wiki down?!
Sebastian Trost via users
Tomcat 10 MLDSA - failed to start
John Mok
Re: Tomcat 10 MLDSA - failed to start
Chuck Caldarale
Re: Tomcat 10 MLDSA - failed to start
Rémy Maucherat
AW: Tomcat 10 MLDSA - failed to start
Döscher, Andreas (ESI) via users
Re: Tomcat 10 MLDSA - failed to start
Rémy Maucherat
AW: Tomcat 10 MLDSA - failed to start
Döscher, Andreas (ESI) via users
[SECURITY] CVE-2026-59084 Apache Tomcat - EncryptInterceptor requirements not clearly documented
Mark Thomas
[SECURITY] CVE-2026-59083 Apache Tomcat - Incorrect URL decoding in RewriteValve may allow security control bypass
Mark Thomas
Multiple Apache Tomcat Vulnerabilities Allow Attackers to Bypass Authentication
Turritopsis Dohrnii Teo En Ming
Re: Multiple Apache Tomcat Vulnerabilities Allow Attackers to Bypass Authentication
Chuck Caldarale
[ANN] Apache Tomcat 10.1.57 Available
Christopher Schultz
[ANN] Apache Tomcat 11.0.24 Available
Mark Thomas
[ANN] Apache Tomcat 9.0.120 available
Rémy Maucherat
tomcat 9.0.119 + jsvc
info . asf
Re: tomcat 9.0.119 + jsvc
Rémy Maucherat
Re: tomcat 9.0.119 + jsvc
Mark Thomas
Re: tomcat 9.0.119 + jsvc
Holger Klawitter
RE: tomcat 9.0.119 + jsvc
Rathore, Rajendra via users
Re: tomcat 9.0.119 + jsvc
Chuck Caldarale
[SECURITY] CVE-2026-55957 Apache Tomcat - Authentication bypass with JNDIRealm and GSSAPI authenticated bind
Mark Thomas
[SECURITY] CVE-2026-55956 Apache Tomcat - Security constraints for default servlet ignored method
Mark Thomas
[SECURITY] CVE-2026-55955 Apache Tomcat - EncryptInterceptor not protected against replay attacks
Mark Thomas
[SECURITY] CVE-2026-55276 Apache Tomcat - Logged effective web.xml is incomplete
Mark Thomas
[SECURITY] CVE-2026-53434 Apache Tomcat - Invalid CRL configuration doesn't trigger failure for FFM Connector
Mark Thomas
[SECURITY] CVE-2026-53404 Apache Tomcat - Bad ornext processing in RewriteValve
Mark Thomas
[SECURITY] CVE-2026-50229 Apache Tomcat - XXS in number guess example
Mark Thomas
Tomcat native 1.3.8
Harri Pesonen via users
Re: Tomcat native 1.3.8
Mark Thomas
Re: Tomcat native 1.3.8
Mark Thomas
Possible regression after upgrade to [9.0.119] (java.lang.IllegalArgumentException: newPosition > limit: (8175 > 9))
Stankov. Yavor
Re: Possible regression after upgrade to [9.0.119] (java.lang.IllegalArgumentException: newPosition > limit: (8175 > 9))
Mark Thomas
Re: Possible regression after upgrade to [9.0.119] (java.lang.IllegalArgumentException: newPosition > limit: (8175 > 9))
Mark Thomas
Interesting issue while deploying an angular application (Tomcat 10.1.x)
Amit Pande via users
Re: Interesting issue while deploying an angular application (Tomcat 10.1.x)
Christopher Schultz
Re: Interesting issue while deploying an angular application (Tomcat 10.1.x)
Mark Thomas
Re: Interesting issue while deploying an angular application (Tomcat 10.1.x)
Amit Pande via users
Re: Interesting issue while deploying an angular application (Tomcat 10.1.x)
Christopher Schultz
Tomcat 10.1.56: Extending RequestElement no longer works!
Amit Pande via users
Re: Tomcat 10.1.56: Extending RequestElement no longer works!
Christopher Schultz
Re: Tomcat 10.1.56: Extending RequestElement no longer works!
Rémy Maucherat
Re: Tomcat 10.1.56: Extending RequestElement no longer works!
Amit Pande via users
Re: Tomcat 10.1.56: Extending RequestElement no longer works!
Christopher Schultz
Re: Tomcat 10.1.56: Extending RequestElement no longer works!
Amit Pande via users
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html Not Yet Updated for 9.0.119
Eddie Rowe via users
Re: https://tomcat.apache.org/tomcat-9.0-doc/changelog.html Not Yet Updated for 9.0.119
Christopher Schultz
Re: https://tomcat.apache.org/tomcat-9.0-doc/changelog.html Not Yet Updated for 9.0.119
Mark Thomas
[ANN] Apache Tomcat 9.0.119 available
Rémy Maucherat
[ANN] Apache Tomcat 10.1.56 Available
Christopher Schultz
[ANN] Apache Tomcat 11.0.23 Available
Mark Thomas
AW: [ANN] Apache Tomcat 11.0.23 Available
Thomas Hoffmann (Speed4Trade GmbH) via users
Re: AW: [ANN] Apache Tomcat 11.0.23 Available
Mark Thomas
Re: AW: [ANN] Apache Tomcat 11.0.23 Available
Mark Thomas
Re: AW: [ANN] Apache Tomcat 11.0.23 Available
Mark Thomas
AW: AW: [ANN] Apache Tomcat 11.0.23 Available
Thomas Hoffmann (Speed4Trade GmbH) via users
[ANN] Apache Tomcat Native 1.3.8 released
Mark Thomas
[ANN] Apache Tomcat Native 2.0.15 released
Mark Thomas
OT: Entra ID Realm for Tomcat
Zoran Avtarovski
Re: OT: Entra ID Realm for Tomcat
Christopher Schultz
Re: OT: Entra ID Realm for Tomcat
Zoran Avtarovski
Re: OT: Entra ID Realm for Tomcat
Christopher Schultz
Re: OT: Entra ID Realm for Tomcat
Zoran Avtarovski
Re: OT: Entra ID Realm for Tomcat
Jon McAlexander
Tomcat website, RSS and social media
Thorsten Heit
Re: Tomcat website, RSS and social media
Mark Thomas
Re: Tomcat website, RSS and social media
Mark Thomas
Re: Tomcat website, RSS and social media
Mark Thomas
Re: Tomcat website, RSS and social media
Christopher Schultz
Re: Tomcat website, RSS and social media
Mark Thomas
Re: RSS
Roger Marquis
Re: RSS
Christopher Schultz
Log headers for failing request
Harri Pesonen via users
Re: Log headers for failing request
Mark Thomas
VS: Log headers for failing request
Harri Pesonen via users
Re: VS: Log headers for failing request
Mark Thomas
VS: VS: Log headers for failing request
Harri Pesonen via users
Re: VS: VS: Log headers for failing request
Mark Thomas
[ANN] Apache Tomcat Migration tool for Jakarta EE 1.0.12
Mark Thomas
Is Tomcat affected by CVE-2026-49975 (HTTP/2 Bomb)?
Stefan Mayr
Re: Is Tomcat affected by CVE-2026-49975 (HTTP/2 Bomb)?
Christopher Schultz
Re: Is Tomcat affected by CVE-2026-49975 (HTTP/2 Bomb)?
Mark Thomas
Re: Is Tomcat affected by CVE-2026-49975 (HTTP/2 Bomb)?
Stefan Mayr
Logging of which jars did or didn't need scanning?
Holle, Jess via users
RE: Logging of which jars did or didn't need scanning?
Hemanta Pathak
RE: Logging of which jars did or didn't need scanning?
Holle, Jess via users
Informal poll of Tomcat version usage
Christopher Schultz
[BUG] Parameters.recycle() does not reset queryStringCharset — leaks across recycled Requests
황인엽
Re: [BUG] Parameters.recycle() does not reset queryStringCharset — leaks across recycled Requests
Mark Thomas
Re: [BUG] Parameters.recycle() does not reset queryStringCharset — leaks across recycled Requests
Mark Thomas
Fwd: Questions regarding updating Apache Tomcat on a server.
Brian Proffitt
Re: Fwd: Questions regarding updating Apache Tomcat on a server.
Jon McAlexander
Re: Fwd: Questions regarding updating Apache Tomcat on a server.
Christopher Schultz
Re: Fwd: Questions regarding updating Apache Tomcat on a server.
Jon McAlexander
Fw: Tomcat Jobs
Jon McAlexander
[SECURITY] CVE-2026-43515 Apache Tomcat - Security constraints not correctly applied
Mark Thomas
[SECURITY] CVE-2026-43514 Apache Tomcat - AJP secret compared in non-constant time
Mark Thomas
[SECURITY] CVE-2026-43513 Apache Tomcat - LockOutRealm treats user names as case-sensitive
Mark Thomas
[SECURITY] CVE-2026-43512 Apache Tomcat - Digest authenticator will authenticate any unknown user
Mark Thomas
[SECURITY] CVE-2026-42498 Apache Tomcat - WebSocket authentication header exposure
Mark Thomas
[SECURITY] CVE-2026-41293 Apache Tomcat - HTTP/2 request headers not validated
Mark Thomas
[SECURITY] CVE-2026-41284 Apache Tomcat - Unbounded read in WebDAV LOCK and PROPFIND handling
Mark Thomas
[ANN] Apache Tomcat 10.1.55 Available
Christopher Schultz
[ANN] Apache Tomcat 9.0.118 available
Rémy Maucherat
[ANN] Apache Tomcat 11.0.22 Available
Mark Thomas
The scheme https s not consistent with the TLS enabled setting (Re: [ANN] Apache Tomcat 11.0.22 Available)
Thomas Meyer
Re: The scheme https s not consistent with the TLS enabled setting (Re: [ANN] Apache Tomcat 11.0.22 Available)
Mark Thomas
Apache Tomcat x.x.x Available?
Mark Foley
Re: Apache Tomcat x.x.x Available?
David Wall
Re: Apache Tomcat x.x.x Available?
Mark Foley
Re: Apache Tomcat x.x.x Available?
Chuck Caldarale
Re: The scheme https s not consistent with the TLS enabled setting (Re: [ANN] Apache Tomcat 11.0.22 Available)
Rémy Maucherat
Re: The scheme https s not consistent with the TLS enabled setting (Re: [ANN] Apache Tomcat 11.0.22 Available)
Mark Thomas
Re: The scheme https s not consistent with the TLS enabled setting (Re: [ANN] Apache Tomcat 11.0.22 Available)
Mark Thomas
Re: The scheme https s not consistent with the TLS enabled setting (Re: [ANN] Apache Tomcat 11.0.22 Available)
Christopher Schultz
Re: The scheme https s not consistent with the TLS enabled setting (Re: [ANN] Apache Tomcat 11.0.22 Available)
Mark Thomas
Earlier messages