[
https://issues.apache.org/jira/browse/TOMEE-4611?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18085399#comment-18085399
]
Markus Jung commented on TOMEE-4611:
------------------------------------
[~rthannee] just merged this in the TomEE 10.x branch, but can't really give an
ETA when we'll roll the next release as we're currently focused on shipping
TomEE 11 M1
> Tomcat 10.1.55
> --------------
>
> Key: TOMEE-4611
> URL: https://issues.apache.org/jira/browse/TOMEE-4611
> Project: TomEE
> Issue Type: Dependency upgrade
> Components: TomEE Core Server
> Reporter: RAJU THANNEERU
> Priority: Major
> Fix For: 10.1.6
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> We see new critical and high issues coming from tomcat 10.1.54
> Vulnerabilities
> ||CVE||CVSS||Severity||Status||Fix Date||Package||Added In||Path||
> |[CVE-2026-41284|https://nvd.nist.gov/vuln/detail/CVE-2026-41284]|7.5|high|fixed
> in 11.0.22, 10.1.55, 10.1.0,...|2026-05-14 23:41:37 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-41293|https://nvd.nist.gov/vuln/detail/CVE-2026-41293]|9.8|critical|fixed
> in 11.0.22, 10.1.55, 10.1.0,...|2026-05-15 19:19:08 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-42498|https://nvd.nist.gov/vuln/detail/CVE-2026-42498]|7.3|high|fixed
> in 11.0.22, 10.1.55, 9.0.118,...|2026-05-14 23:41:37 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-43512|https://nvd.nist.gov/vuln/detail/CVE-2026-43512]|9.8|critical|fixed
> in 11.0.22, 10.1.55, 9.0.118,...|2026-05-15 19:19:08 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-43513|https://nvd.nist.gov/vuln/detail/CVE-2026-43513]|7.5|high|fixed
> in 11.0.22, 10.1.55, 9.0.118,...|2026-05-15 19:19:08 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-43514|https://nvd.nist.gov/vuln/detail/CVE-2026-43514]|3.7|low|fixed
> in 11.0.22, 10.1.55, 9.0.118,...|2026-05-14 23:41:37 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-43515|https://nvd.nist.gov/vuln/detail/CVE-2026-43515]|9.1|critical|fixed
> in 11.0.22, 10.1.55, 9.0.118,...|2026-05-15 19:19:08 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
--
This message was sent by Atlassian Jira
(v8.20.10#820010)