[
https://issues.apache.org/jira/browse/TOMEE-4611?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18090562#comment-18090562
]
RAJU THANNEERU commented on TOMEE-4611:
---------------------------------------
Hi [~jungm], looks like TomEE 11 M1 is released, do we have any timeline for
10.1.6.
We see new critical and high issues
|[CVE-2026-40466|https://nvd.nist.gov/vuln/detail/CVE-2026-40466]|8.8|high|fixed
in 6.2.5, 5.19.6|2026-05-05 07:22:45 +0000
UTC|[org.apache.activemq_activemq-broker_6.2.4|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.activemq_activemq-broker_6.2.4]|this
image|/usr/local/tomee/lib/activemq-broker-6.2.4.jar|
|[CVE-2026-41043|https://nvd.nist.gov/vuln/detail/CVE-2026-41043]|6.5|medium|fixed
in 6.2.5, 5.19.6|2026-05-05 07:22:45 +0000
UTC|[org.apache.activemq_activemq-broker_6.2.4|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.activemq_activemq-broker_6.2.4]|this
image|/usr/local/tomee/lib/activemq-broker-6.2.4.jar|
|[CVE-2026-41044|https://nvd.nist.gov/vuln/detail/CVE-2026-41044]|8.8|high|fixed
in 6.2.5, 5.19.6|2026-05-05 07:22:45 +0000
UTC|[org.apache.activemq_activemq-broker_6.2.4|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.activemq_activemq-broker_6.2.4]|this
image|/usr/local/tomee/lib/activemq-broker-6.2.4.jar|
|[CVE-2026-40466|https://nvd.nist.gov/vuln/detail/CVE-2026-40466]|8.8|high|fixed
in 6.2.5, 5.19.6|2026-04-27 15:30:58 +0000
UTC|[org.apache.activemq_activemq-client_6.2.4|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.activemq_activemq-client_6.2.4]|this
image|/usr/local/tomee/lib/activemq-client-6.2.4.jar|
|[CVE-2026-41043|https://nvd.nist.gov/vuln/detail/CVE-2026-41043]|6.5|medium|fixed
in 6.2.5, 5.19.6|2026-04-27 19:42:35 +0000
UTC|[org.apache.activemq_activemq-client_6.2.4|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.activemq_activemq-client_6.2.4]|this
image|/usr/local/tomee/lib/activemq-client-6.2.4.jar|
|[CVE-2026-41044|https://nvd.nist.gov/vuln/detail/CVE-2026-41044]|8.8|high|fixed
in 6.2.5, 5.19.6|2026-04-27 19:42:35 +0000
UTC|[org.apache.activemq_activemq-client_6.2.4|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.activemq_activemq-client_6.2.4]|this
image|/usr/local/tomee/lib/activemq-client-6.2.4.jar|
|[CVE-2026-42253|https://nvd.nist.gov/vuln/detail/CVE-2026-42253]|6.1|medium|fixed
in 6.2.6, 5.19.7|2026-06-02 00:11:04 +0000
UTC|[org.apache.activemq_activemq-client_6.2.4|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.activemq_activemq-client_6.2.4]|this
image|/usr/local/tomee/lib/activemq-client-6.2.4.jar|
|[CVE-2026-42588|https://nvd.nist.gov/vuln/detail/CVE-2026-42588]|8.1|high|fixed
in 6.2.6, 5.19.7|2026-06-02 00:11:04 +0000
UTC|[org.apache.activemq_activemq-client_6.2.4|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.activemq_activemq-client_6.2.4]|this
image|/usr/local/tomee/lib/activemq-client-6.2.4.jar|
|[CVE-2026-45505|https://nvd.nist.gov/vuln/detail/CVE-2026-45505]|8.8|high|fixed
in 6.2.6, 5.19.7|2026-06-02 00:11:04 +0000
UTC|[org.apache.activemq_activemq-client_6.2.4|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.activemq_activemq-client_6.2.4]|this
image|/usr/local/tomee/lib/activemq-client-6.2.4.jar|
|[CVE-2026-46605|https://nvd.nist.gov/vuln/detail/CVE-2026-46605]|4.3|medium|fixed
in 6.2.6, 5.19.7|2026-06-02 00:11:04 +0000
UTC|[org.apache.activemq_activemq-client_6.2.4|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.activemq_activemq-client_6.2.4]|this
image|/usr/local/tomee/lib/activemq-client-6.2.4.jar|
|[CVE-2026-49157|https://nvd.nist.gov/vuln/detail/CVE-2026-49157]|8.8|high|fixed
in 6.2.6, 5.19.7|2026-06-02 00:11:04 +0000
UTC|[org.apache.activemq_activemq-client_6.2.4|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.activemq_activemq-client_6.2.4]|this
image|/usr/local/tomee/lib/activemq-client-6.2.4.jar|
|[CVE-2026-49270|https://nvd.nist.gov/vuln/detail/CVE-2026-49270]|5.9|medium|fixed
in 6.2.6, 5.19.7|2026-06-02 00:11:04 +0000
UTC|[org.apache.activemq_activemq-client_6.2.4|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.activemq_activemq-client_6.2.4]|this
image|/usr/local/tomee/lib/activemq-client-6.2.4.jar|
|[CVE-2026-44417|https://nvd.nist.gov/vuln/detail/CVE-2026-44417]|7.5|high|fixed
in 4.2.1, 4.1.6, 3.6.11|2026-05-26 20:21:30 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-44618|https://nvd.nist.gov/vuln/detail/CVE-2026-44618]|5.3|medium|fixed
in 4.2.1, 4.1.6, 3.6.11|2026-05-26 20:21:30 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-44930|https://nvd.nist.gov/vuln/detail/CVE-2026-44930]|9.8|critical|fixed
in 4.2.1, 4.1.6, 3.6.11|2026-05-26 20:21:30 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-49875|https://nvd.nist.gov/vuln/detail/CVE-2026-49875]|9.8|critical|fixed
in 4.2.2, 4.1.7|2026-06-15 22:32:37 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-50623|https://nvd.nist.gov/vuln/detail/CVE-2026-50623]|4.8|medium|fixed
in 4.2.2, 4.1.7|2026-06-13 00:53:02 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-50627|https://nvd.nist.gov/vuln/detail/CVE-2026-50627]|9.1|critical|fixed
in 4.2.2, 4.1.7|2026-06-15 22:32:37 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-50628|https://nvd.nist.gov/vuln/detail/CVE-2026-50628]|9.8|critical|fixed
in 4.2.2, 4.1.7|2026-06-15 22:32:37 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-50629|https://nvd.nist.gov/vuln/detail/CVE-2026-50629]|5.3|medium|fixed
in 4.2.2, 4.1.7|2026-06-13 00:53:02 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-50630|https://nvd.nist.gov/vuln/detail/CVE-2026-50630]|6.5|medium|fixed
in 4.2.2, 4.1.7|2026-06-13 00:53:02 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-50631|https://nvd.nist.gov/vuln/detail/CVE-2026-50631]|7.4|high|fixed
in 4.2.2, 4.1.7|2026-06-13 00:53:02 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-50632|https://nvd.nist.gov/vuln/detail/CVE-2026-50632]|8.1|high|fixed
in 4.2.2, 4.1.7|2026-06-13 00:53:02 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-50633|https://nvd.nist.gov/vuln/detail/CVE-2026-50633]|8.1|high|fixed
in 4.2.2, 4.1.7|2026-06-13 00:53:02 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-50634|https://nvd.nist.gov/vuln/detail/CVE-2026-50634]|6.5|medium|fixed
in 4.2.2, 4.1.7|2026-06-13 00:53:02 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-50645|https://nvd.nist.gov/vuln/detail/CVE-2026-50645]|7.5|high|fixed
in 4.2.2, 4.1.7|2026-06-13 07:38:38 +0000
UTC|[org.apache.cxf_cxf-core_4.1.5|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.cxf_cxf-core_4.1.5]|this
image|/usr/local/tomee/lib/cxf-core-4.1.5.jar|
|[CVE-2026-42402|https://nvd.nist.gov/vuln/detail/CVE-2026-42402]|7.5|high|fixed
in 3.2.2|2026-05-07 12:53:20 +0000
UTC|[org.apache.neethi_neethi_3.2.1|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.neethi_neethi_3.2.1]|this
image|/usr/local/tomee/lib/neethi-3.2.1.jar|
|[CVE-2026-42403|https://nvd.nist.gov/vuln/detail/CVE-2026-42403]|7.5|high|fixed
in 3.2.2|2026-05-07 12:53:20 +0000
UTC|[org.apache.neethi_neethi_3.2.1|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.neethi_neethi_3.2.1]|this
image|/usr/local/tomee/lib/neethi-3.2.1.jar|
|[CVE-2026-42404|https://nvd.nist.gov/vuln/detail/CVE-2026-42404]|6.5|medium|fixed
in 3.2.2|2026-05-07 12:53:20 +0000
UTC|[org.apache.neethi_neethi_3.2.1|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_org.apache.neethi_neethi_3.2.1]|this
image|/usr/local/tomee/lib/neethi-3.2.1.jar|
|[CVE-2026-45292|https://nvd.nist.gov/vuln/detail/CVE-2026-45292]|5.3|medium|fixed
in 1.62.0|2026-05-14 23:41:37 +0000
UTC|[opentelemetry-api_1.32.0|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_opentelemetry-api_1.32.0]|this
image|/usr/local/tomee/lib/opentelemetry-api-1.32.0.jar|
|[CVE-2026-41284|https://nvd.nist.gov/vuln/detail/CVE-2026-41284]|7.5|high|fixed
in 11.0.22, 10.1.55, 10.1.0,...|2026-05-14 23:41:37 +0000
UTC|[tomcat-util_10.1.54|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_tomcat-util_10.1.54]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-41293|https://nvd.nist.gov/vuln/detail/CVE-2026-41293]|9.8|critical|fixed
in 11.0.22, 10.1.55, 10.1.0,...|2026-05-15 19:19:08 +0000
UTC|[tomcat-util_10.1.54|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_tomcat-util_10.1.54]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-42498|https://nvd.nist.gov/vuln/detail/CVE-2026-42498]|7.3|high|fixed
in 11.0.22, 10.1.55, 9.0.118,...|2026-05-14 23:41:37 +0000
UTC|[tomcat-util_10.1.54|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_tomcat-util_10.1.54]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-43512|https://nvd.nist.gov/vuln/detail/CVE-2026-43512]|9.8|critical|fixed
in 11.0.22, 10.1.55, 9.0.118,...|2026-05-15 19:19:08 +0000
UTC|[tomcat-util_10.1.54|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_tomcat-util_10.1.54]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-43513|https://nvd.nist.gov/vuln/detail/CVE-2026-43513]|7.5|high|fixed
in 11.0.22, 10.1.55, 9.0.118,...|2026-05-15 19:19:08 +0000
UTC|[tomcat-util_10.1.54|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_tomcat-util_10.1.54]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-43514|https://nvd.nist.gov/vuln/detail/CVE-2026-43514]|3.7|low|fixed
in 11.0.22, 10.1.55, 9.0.118,...|2026-05-14 23:41:37 +0000
UTC|[tomcat-util_10.1.54|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_tomcat-util_10.1.54]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-43515|https://nvd.nist.gov/vuln/detail/CVE-2026-43515]|9.1|critical|fixed
in 11.0.22, 10.1.55, 9.0.118,...|2026-05-15 19:19:08 +0000
UTC|[tomcat-util_10.1.54|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:c60912df7fcae9d3fd9d3049ba64672d00cf142d190e7ce6b7d23dcc66aa471a_tomcat-util_10.1.54]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
> Tomcat 10.1.55
> --------------
>
> Key: TOMEE-4611
> URL: https://issues.apache.org/jira/browse/TOMEE-4611
> Project: TomEE
> Issue Type: Dependency upgrade
> Components: TomEE Core Server
> Reporter: RAJU THANNEERU
> Priority: Major
> Fix For: 10.1.6
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> We see new critical and high issues coming from tomcat 10.1.54
> Vulnerabilities
> ||CVE||CVSS||Severity||Status||Fix Date||Package||Added In||Path||
> |[CVE-2026-41284|https://nvd.nist.gov/vuln/detail/CVE-2026-41284]|7.5|high|fixed
> in 11.0.22, 10.1.55, 10.1.0,...|2026-05-14 23:41:37 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-41293|https://nvd.nist.gov/vuln/detail/CVE-2026-41293]|9.8|critical|fixed
> in 11.0.22, 10.1.55, 10.1.0,...|2026-05-15 19:19:08 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-42498|https://nvd.nist.gov/vuln/detail/CVE-2026-42498]|7.3|high|fixed
> in 11.0.22, 10.1.55, 9.0.118,...|2026-05-14 23:41:37 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-43512|https://nvd.nist.gov/vuln/detail/CVE-2026-43512]|9.8|critical|fixed
> in 11.0.22, 10.1.55, 9.0.118,...|2026-05-15 19:19:08 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-43513|https://nvd.nist.gov/vuln/detail/CVE-2026-43513]|7.5|high|fixed
> in 11.0.22, 10.1.55, 9.0.118,...|2026-05-15 19:19:08 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-43514|https://nvd.nist.gov/vuln/detail/CVE-2026-43514]|3.7|low|fixed
> in 11.0.22, 10.1.55, 9.0.118,...|2026-05-14 23:41:37 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
> |[CVE-2026-43515|https://nvd.nist.gov/vuln/detail/CVE-2026-43515]|9.1|critical|fixed
> in 11.0.22, 10.1.55, 9.0.118,...|2026-05-15 19:19:08 +0000
> UTC|[tomcat-util_10.1.54|https://otscan.otxlab.net/api/v1/scan/c0feeaee-6ca0-4d14-98ee-326106af0b99/report/html#sha256:1003b350658808dc00e5e231b31f63a05ea8cf225976543bc7a5b3299e2905e9_tomcat-util_10.1.54]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
--
This message was sent by Atlassian Jira
(v8.20.10#820010)