[ 
https://issues.apache.org/jira/browse/TOMEE-4611?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18083389#comment-18083389
 ] 

RAJU THANNEERU commented on TOMEE-4611:
---------------------------------------

Hi [~jungm], do we have any ETA for next TomEE release as we see multiple 
critical and high security issues.

> Tomcat 10.1.55
> --------------
>
>                 Key: TOMEE-4611
>                 URL: https://issues.apache.org/jira/browse/TOMEE-4611
>             Project: TomEE
>          Issue Type: Dependency upgrade
>          Components: TomEE Core Server
>            Reporter: RAJU THANNEERU
>            Priority: Major
>             Fix For: 10.1.6
>
>
> We see new critical and high issues coming from tomcat 10.1.54
> Vulnerabilities
> ||CVE||CVSS||Severity||Status||Fix Date||Package||Added In||Path||
> |[CVE-2026-41284|https://nvd.nist.gov/vuln/detail/CVE-2026-41284]|7.5|high|fixed
>  in 11.0.22, 10.1.55, 10.1.0,...|2026-05-14 23:41:37 +0000 
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
>  image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-41293|https://nvd.nist.gov/vuln/detail/CVE-2026-41293]|9.8|critical|fixed
>  in 11.0.22, 10.1.55, 10.1.0,...|2026-05-15 19:19:08 +0000 
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
>  image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-42498|https://nvd.nist.gov/vuln/detail/CVE-2026-42498]|7.3|high|fixed
>  in 11.0.22, 10.1.55, 9.0.118,...|2026-05-14 23:41:37 +0000 
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
>  image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-43512|https://nvd.nist.gov/vuln/detail/CVE-2026-43512]|9.8|critical|fixed
>  in 11.0.22, 10.1.55, 9.0.118,...|2026-05-15 19:19:08 +0000 
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
>  image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-43513|https://nvd.nist.gov/vuln/detail/CVE-2026-43513]|7.5|high|fixed
>  in 11.0.22, 10.1.55, 9.0.118,...|2026-05-15 19:19:08 +0000 
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
>  image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-43514|https://nvd.nist.gov/vuln/detail/CVE-2026-43514]|3.7|low|fixed
>  in 11.0.22, 10.1.55, 9.0.118,...|2026-05-14 23:41:37 +0000 
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
>  image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-43515|https://nvd.nist.gov/vuln/detail/CVE-2026-43515]|9.1|critical|fixed
>  in 11.0.22, 10.1.55, 9.0.118,...|2026-05-15 19:19:08 +0000 
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
>  image|/usr/local/tomee/lib/tomcat-util.jar|



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to