- What: Tomcat10 receives multiple security updates
- Impact: Fixes vulnerabilities in the web server
[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6328-1] tomcat10 security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6328-1] tomcat10 security update From: Markus Koschany <apo@debian.org> Date: Mon, 8 Jun 2026 12:57:54 +0000 Message-id: <[🔎] aia8UvaiTA0mWRLO@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6328-1 security@debian.org https://www.debian.org/security/ Markus Koschany June 08, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tomcat10 CVE ID : CVE-2026-24880 CVE-2026-25854 CVE-2026-29129 CVE-2026-29145 CVE-2026-29146 CVE-2026-32990 CVE-2026-34483 CVE-2026-34487 CVE-2026-34500 CVE-2026-41284 CVE-2026-41293 CVE-2026-42498 CVE-2026-43512 CVE-2026-43513 CVE-2026-43514 CVE-2026-43515 Multiple security vulnerabilities have been discovered in Tomcat 10, a Java based web server, servlet and JSP engine which may result in a denial of service, authentication bypass or the disclosure of sensitive information. Although we are not aware of any problems, new upstream versions may introduce new options, limits or code changes which may or may not affect your existing web applications. We recommend to consult the Tomcat 10 documentation for further information. For the oldstable distribution (bookworm), these problems have been fixed in version 10.1.55-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 10.1.55-1~deb13u1. We recommend that you upgrade your tomcat10 packages. For the detailed security status of tomcat10 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/tomcat10 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmomtKFfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7 UeQslg//eJAcasr5bsLEyDpJ61EzUdMPJqNuXeVOFk7xwNAkAEN/tHdZtFjeUzzL 5yodji95t0OmzMPd3wYuMuGVVlByfiY8QnFrUvGeGh16Z3iW6OAbZDK/RIO8J4LF WwFVOigeekw8ZKEJA+KAzlX8SEVQ8DQx+y/PGyoPe5K1O30yVCQMbBY9zcQfzFe6 PsibTi+ZjKZSE5UUKtHFY/9ujODmSIv4XZ30yptibU9OD0HmAJkMUVbZWyr1foTS C8pDf/+24umt5VCtV0pLw7azfzLyEKtUhunCHrRw2UcV3I1WHkgC/61mTc33+XTK TfDWFpcUxTa7dj9UzpNN3Dw8/vkwCP6L3uS7ZBDY6HDh7+EjGTdWLnHnXgaKA8oe JuJ32xvZo9HrQdmPRdJC1Poil/5cssssUBkjU7RNKjLAKILqy7FWLmTvpB+0ptv4 c9BeBDsyqbhf4s/tpBEfJwM5LCxq3V9iL8nK2Rvn02kbkYI+Z6uvcj7E1vd0tZYi L94tXVXO/U2o2J+xwVGw4ZgI+E1mGUHgda/JFa+3Kr4Ts/fNzfOKHjJmAnOfUzPd 22k5Ewcy0a7c1uGuNFNqA851TsQ52eyYuyVN2fzE1GHPt2XaLlVexKRHrnGNGHTp RxEThbwNgJvczPbJ2LABFNez2mjQLkZHsMQE5VFq3NSiqyhDAY0= =WgrD -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Markus Koschany (on-list) Markus Koschany (off-list) Prev by Date: [SECURITY] [DSA 6327-1] request-tracker4 security update Next by Date: [SECURITY] [DSA 6329-1] tomcat11 security update Previous by thread: [SECURITY] [DSA 6327-1] request-tracker4 security update Next by thread: [SECURITY] [DSA 6329-1] tomcat11 security update Index(es): Date Thread