users
Thread
Date
Earlier messages
Messages by Thread
Tomcat 11: HttpParser.readHostIPv4 always throws ArrayIndexOutOfBoundsException during IPv4 host parsing
Chunhui Liu
Re: Tomcat 11: HttpParser.readHostIPv4 always throws ArrayIndexOutOfBoundsException during IPv4 host parsing
Mark Thomas
Re: Tomcat 11: HttpParser.readHostIPv4 always throws ArrayIndexOutOfBoundsException during IPv4 host parsing
Chunhui Liu
Re: Tomcat 11: HttpParser.readHostIPv4 always throws ArrayIndexOutOfBoundsException during IPv4 host parsing
Mark Thomas
Re: Tomcat 11: HttpParser.readHostIPv4 always throws ArrayIndexOutOfBoundsException during IPv4 host parsing
Chunhui Liu
Problems after OCSP changes in Tomcat Native 2.0.16
logo
Re: Problems after OCSP changes in Tomcat Native 2.0.16
Stefan Mayr
Re: Problems after OCSP changes in Tomcat Native 2.0.16
Mark Thomas
Re: Problems after OCSP changes in Tomcat Native 2.0.16
logo
Re: Problems after OCSP changes in Tomcat Native 2.0.16
Mark Thomas
Re: Problems after OCSP changes in Tomcat Native 2.0.16
Peter Kreuser
Questions regarding Mail Security SPF/DMARC and tomcat group emails
logo
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
Mark Thomas
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
logo
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
logo
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
logo
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
Torsten Krah
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
Mark Thomas
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
Piotr P. Karwasz
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
Peter Kreuser
[ANN] Apache Tomcat 9.0.122 available
Rémy Maucherat
Re: [ANN] Apache Tomcat 9.0.122 available
Andrei Ivanov
Re: [ANN] Apache Tomcat 9.0.122 available
Mark Thomas
[ANN] Apache Tomcat 11.0.26 Available
Mark Thomas
Re: [ANN] Apache Tomcat 11.0.26 Available - libtcnative location
Evan Rempel via users
Re: [ANN] Apache Tomcat 11.0.26 Available - libtcnative location
Mark Thomas
[ANN] Apache Tomcat 10.1.60 Available
Christopher Schultz
[ANN] Apache Tomcat Native 1.3.9 released
Mark Thomas
Re: [ANN] Apache Tomcat Native 1.3.9 released
Evan Rempel via users
Re: [ANN] Apache Tomcat Native 1.3.9 released
Mark Thomas
Re: [ANN] Apache Tomcat Native 1.3.9 released
Evan Rempel via users
Re: [ANN] Apache Tomcat Native 1.3.9 released
Noelette Stout
Re: [ANN] Apache Tomcat Native 1.3.9 released
Evan Rempel via users
Re: [ANN] Apache Tomcat Native 1.3.9 released
logo
[ANN] Apache Tomcat Native 2.0.16 released
Mark Thomas
Re: [ANN] Apache Tomcat Native 2.0.16 released
Simon Matter
Re: [ANN] Apache Tomcat Native 2.0.16 released
logo
Re: [ANN] Apache Tomcat Native 2.0.16 released
Mark Thomas
Re: [ANN] Apache Tomcat Native 2.0.16 released
Simon Matter
Re: [ANN] Apache Tomcat Native 2.0.16 released
Mark Thomas
Tomcat Severity Ratings verus CVSS
Darryl Baker
Re: Tomcat Severity Ratings verus CVSS
[email protected]
Re: Tomcat Severity Ratings verus CVSS
Christopher Schultz
Re: Tomcat Severity Ratings verus CVSS
Darryl Baker
[SECURITY] CVE-2026-73180 Apache Tomcat - Authenticated WebSocket session survives end of HTTP session
Mark Thomas
[SECURITY] CVE-2026-68763 Apache Tomcat - DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
Mark Thomas
[SECURITY] CVE-2026-68569 Apache Tomcat - Principal lookup can fail open in some cases
Mark Thomas
[SECURITY] CVE-2026-68525 Apache Tomcat - Redirect after FORM authentication may bypass method specific constraints
Mark Thomas
[SECURITY] CVE-2026-66422 Apache Tomcat - Servlet role references can bypass declarative role constraints
Mark Thomas
[SECURITY] CVE-2026-65927 Apache Tomcat - RewriteValve [N] restarts at the second rule and may bypass access control
Mark Thomas
[SECURITY] CVE-2026-65905 Apache Tomcat - Limited replay attack possible with DIGEST authentication
Mark Thomas
[SECURITY] CVE-2026-65637 Apache Tomcat - HTTP/2 no-authority bypass of strict SNI validation
Mark Thomas
[SECURITY] CVE-2026-65183 Apache Tomcat - TOCTOU when setting specific permissions for Unix Domain Sockets
Mark Thomas
[SECURITY] CVE-2026-65182 Apache Tomcat - Security constraint bypass
Mark Thomas
Support for gMSA
Lambert, Dominique via users
Re: Support for gMSA
Mark Thomas
RE: Support for gMSA
Lambert, Dominique via users
Fwd: Version 10.1.57 / 10.1.59
Brian Proffitt
AW: Version 10.1.57 / 10.1.59
Thomas Hoffmann (Speed4Trade GmbH) via users
Re: AW: Version 10.1.57 / 10.1.59
Mark Thomas
Update for new versions
Venkumahanti Praveen
Re: Update for new versions
Mark Thomas
Tomcat Embed Core 10.1.58
Raghu Dev
Re: Tomcat Embed Core 10.1.58
Chuck Caldarale
Re: Tomcat Embed Core 10.1.58
Eric Fetzer
Re: Tomcat Embed Core 10.1.58
Mark Thomas
Re: Tomcat Embed Core 10.1.58
Eric Fetzer
Re: Tomcat Embed Core 10.1.58
Christopher Schultz
Re: Tomcat Embed Core 10.1.58
Roger Marquis
Re: Tomcat Embed Core 10.1.58
Mark Thomas
[ANN] Apache Tomcat 9.0.121 available
Rémy Maucherat
[ANN] Apache Tomcat 11.0.25 Available
Mark Thomas
Status and timeline inquiry for Apache Tomcat 11.0.25 release
Terry ST SY/DPO
Re: Status and timeline inquiry for Apache Tomcat 11.0.25 release
Chuck Caldarale
Tomcat 11.0.25 Release Timeline Inquiry
joao-paulo.martins-prestataire.ca-ps.com via users
Re: Tomcat 11.0.25 Release Timeline Inquiry
Sebastian Trost via users
Re: Tomcat 11.0.25 Release Timeline Inquiry
Jo�o Paulo Sim�es Martins via users
Re: Tomcat 11.0.25 Release Timeline Inquiry
Mark Thomas
Re: Tomcat 11.0.25 Release Timeline Inquiry
Christopher Schultz
Session clustering between tomcat versions.
Stephen Booth
Re: Session clustering between tomcat versions.
Mark Thomas
Regarding apache-tomcat 10.1.58 version
Roshan Patil
AW: Regarding apache-tomcat 10.1.58 version
Döscher, Andreas (ESI) via users
Re: AW: Regarding apache-tomcat 10.1.58 version
Roshan Patil
Re: Regarding apache-tomcat 10.1.58 version
Rob Sargent
Re: AW: Regarding apache-tomcat 10.1.58 version
Mark Thomas
Regarding apache-tomcat 10.1.58 version
Roshan Patil
Re: Regarding apache-tomcat 10.1.58 version
Mark Thomas
Community over Code Sydney 2026
Mark Thomas
Re: Community over Code Sydney 2026
Mark Thomas
Community over Code Glasgow 2026
Mark Thomas
[SECURITY] CVE-2026-66299 Apache Tomcat - DoS via WebSocket chat example
Mark Thomas
London - Tues 28 July - evening
Mark Thomas
Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
LAURIA Giuseppe via users
Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Tim Funk
AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
LAURIA Giuseppe via users
Re: AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Sebastian Trost via users
Re: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Peter Kreuser
Re: AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Mark Thomas
Re: AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Rémy Maucherat
AW: [EXTERNAL] Re: AW: Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
LAURIA Giuseppe via users
Re: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Zdeněk Henek
Re: AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Christopher Schultz
Tomcat Jobs?
Jon McAlexander
Re: Tomcat Jobs?
Sebastian Trost via users
Re: Tomcat Jobs?
Jon McAlexander
Re: Tomcat Jobs?
Sebastian Trost via users
Possible missing CVE commits in 9.0.120, 10.1.57 and 11.0.24 release builds
Thomas Williams
Re: Possible missing CVE commits in 9.0.120, 10.1.57 and 11.0.24 release builds
Mark Thomas
Apache Tomcat 9.1.x release timeframe
Lisa Sayre
Re: Apache Tomcat 9.1.x release timeframe
Mark Thomas
Re: Apache Tomcat 9.1.x release timeframe
david w
RE: Apache Tomcat 9.1.x release timeframe
Lisa Sayre
Re: Apache Tomcat 9.1.x release timeframe
Sebastian Trost via users
RE: Apache Tomcat 9.1.x release timeframe
Eddie Rowe via users
Re: Apache Tomcat 9.1.x release timeframe
Mark Thomas
RE: Apache Tomcat 9.1.x release timeframe
Lisa Sayre
Re: Apache Tomcat 9.1.x release timeframe
Mark Thomas
RE: Apache Tomcat 9.1.x release timeframe
Lisa Sayre
Re: Apache Tomcat 9.1.x release timeframe
Christopher Schultz
Re: Apache Tomcat 9.1.x release timeframe
Sebastian Trost via users
Re: [OT] Apache Tomcat 9.1.x release timeframe
Christopher Schultz
Re: Apache Tomcat 9.1.x release timeframe
Christopher Schultz
Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Olaf Kock
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
Christopher Schultz
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
GUSTAVO AVITABILE
Re: Tomcat host header redirect issue
GUSTAVO AVITABILE
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
Christopher Schultz
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Christopher Schultz
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
Johan Compagner
jspwiki-wiki down?!
Holger Klawitter
Re: jspwiki-wiki down?!
Sebastian Trost via users
Tomcat 10 MLDSA - failed to start
John Mok
Re: Tomcat 10 MLDSA - failed to start
Chuck Caldarale
Re: Tomcat 10 MLDSA - failed to start
Rémy Maucherat
AW: Tomcat 10 MLDSA - failed to start
Döscher, Andreas (ESI) via users
Re: Tomcat 10 MLDSA - failed to start
Rémy Maucherat
AW: Tomcat 10 MLDSA - failed to start
Döscher, Andreas (ESI) via users
[SECURITY] CVE-2026-59084 Apache Tomcat - EncryptInterceptor requirements not clearly documented
Mark Thomas
[SECURITY] CVE-2026-59083 Apache Tomcat - Incorrect URL decoding in RewriteValve may allow security control bypass
Mark Thomas
Multiple Apache Tomcat Vulnerabilities Allow Attackers to Bypass Authentication
Turritopsis Dohrnii Teo En Ming
Re: Multiple Apache Tomcat Vulnerabilities Allow Attackers to Bypass Authentication
Chuck Caldarale
[ANN] Apache Tomcat 10.1.57 Available
Christopher Schultz
[ANN] Apache Tomcat 11.0.24 Available
Mark Thomas
[ANN] Apache Tomcat 9.0.120 available
Rémy Maucherat
tomcat 9.0.119 + jsvc
info . asf
Re: tomcat 9.0.119 + jsvc
Rémy Maucherat
Re: tomcat 9.0.119 + jsvc
Mark Thomas
Re: tomcat 9.0.119 + jsvc
Holger Klawitter
RE: tomcat 9.0.119 + jsvc
Rathore, Rajendra via users
Re: tomcat 9.0.119 + jsvc
Chuck Caldarale
[SECURITY] CVE-2026-55957 Apache Tomcat - Authentication bypass with JNDIRealm and GSSAPI authenticated bind
Mark Thomas
[SECURITY] CVE-2026-55956 Apache Tomcat - Security constraints for default servlet ignored method
Mark Thomas
[SECURITY] CVE-2026-55955 Apache Tomcat - EncryptInterceptor not protected against replay attacks
Mark Thomas
[SECURITY] CVE-2026-55276 Apache Tomcat - Logged effective web.xml is incomplete
Mark Thomas
[SECURITY] CVE-2026-53434 Apache Tomcat - Invalid CRL configuration doesn't trigger failure for FFM Connector
Mark Thomas
[SECURITY] CVE-2026-53404 Apache Tomcat - Bad ornext processing in RewriteValve
Mark Thomas
[SECURITY] CVE-2026-50229 Apache Tomcat - XXS in number guess example
Mark Thomas
Tomcat native 1.3.8
Harri Pesonen via users
Re: Tomcat native 1.3.8
Mark Thomas
Re: Tomcat native 1.3.8
Mark Thomas
Possible regression after upgrade to [9.0.119] (java.lang.IllegalArgumentException: newPosition > limit: (8175 > 9))
Stankov. Yavor
Re: Possible regression after upgrade to [9.0.119] (java.lang.IllegalArgumentException: newPosition > limit: (8175 > 9))
Mark Thomas
Re: Possible regression after upgrade to [9.0.119] (java.lang.IllegalArgumentException: newPosition > limit: (8175 > 9))
Mark Thomas
Interesting issue while deploying an angular application (Tomcat 10.1.x)
Amit Pande via users
Re: Interesting issue while deploying an angular application (Tomcat 10.1.x)
Christopher Schultz
Re: Interesting issue while deploying an angular application (Tomcat 10.1.x)
Mark Thomas
Re: Interesting issue while deploying an angular application (Tomcat 10.1.x)
Amit Pande via users
Re: Interesting issue while deploying an angular application (Tomcat 10.1.x)
Christopher Schultz
Tomcat 10.1.56: Extending RequestElement no longer works!
Amit Pande via users
Re: Tomcat 10.1.56: Extending RequestElement no longer works!
Christopher Schultz
Re: Tomcat 10.1.56: Extending RequestElement no longer works!
Rémy Maucherat
Re: Tomcat 10.1.56: Extending RequestElement no longer works!
Amit Pande via users
Re: Tomcat 10.1.56: Extending RequestElement no longer works!
Christopher Schultz
Re: Tomcat 10.1.56: Extending RequestElement no longer works!
Amit Pande via users
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html Not Yet Updated for 9.0.119
Eddie Rowe via users
Re: https://tomcat.apache.org/tomcat-9.0-doc/changelog.html Not Yet Updated for 9.0.119
Christopher Schultz
Re: https://tomcat.apache.org/tomcat-9.0-doc/changelog.html Not Yet Updated for 9.0.119
Mark Thomas
[ANN] Apache Tomcat 9.0.119 available
Rémy Maucherat
[ANN] Apache Tomcat 10.1.56 Available
Christopher Schultz
[ANN] Apache Tomcat 11.0.23 Available
Mark Thomas
AW: [ANN] Apache Tomcat 11.0.23 Available
Thomas Hoffmann (Speed4Trade GmbH) via users
Re: AW: [ANN] Apache Tomcat 11.0.23 Available
Mark Thomas
Re: AW: [ANN] Apache Tomcat 11.0.23 Available
Mark Thomas
Re: AW: [ANN] Apache Tomcat 11.0.23 Available
Mark Thomas
AW: AW: [ANN] Apache Tomcat 11.0.23 Available
Thomas Hoffmann (Speed4Trade GmbH) via users
Earlier messages