Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
9ae64f4a by Moritz Muehlenhoff at 2026-08-08T14:09:03+02:00
tomcat11 fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -22516,7 +22516,7 @@ CVE-2026-59197 (Pillow is a Python imaging library. 
Prior to 12.3.0, Pillow's pu
        NOTE: https://github.com/python-pillow/Pillow/pull/9695
        NOTE: Fixed by: 
https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1
 (12.3.0)
 CVE-2026-59084 (Insufficient Technical Documentation vulnerability in Apache 
Tomcat si ...)
-       - tomcat11 <unfixed> (bug #1142454)
+       - tomcat11 11.0.24-1 (bug #1142454)
        - tomcat10 <unfixed> (bug #1142455)
        - tomcat9 9.0.70-2
        NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server 
stack, using that as the fixed version
@@ -22524,7 +22524,7 @@ CVE-2026-59084 (Insufficient Technical Documentation 
vulnerability in Apache Tom
        NOTE: 
https://github.com/apache/tomcat/commit/79466463f18cf57704513a5aaa93961bf14c9ef5
 (10.1.57)
        NOTE: 
https://github.com/apache/tomcat/commit/617d7275782bf58b45f6b7ea82c2edf16660e0b3
 (9.0.120)
 CVE-2026-59083 (Improper Handling of URL Encoding (Hex Encoding) vulnerability 
in Apac ...)
-       - tomcat11 <unfixed> (bug #1142454)
+       - tomcat11 11.0.24-1 (bug #1142454)
        - tomcat10 <unfixed> (bug #1142455)
        - tomcat9 9.0.70-2
        NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server 
stack, using that as the fixed version
@@ -34482,7 +34482,7 @@ CVE-2026-10648 (mcumgr_serial_process_frag() in 
subsys/mgmt/mcumgr/transport/src
 CVE-2026-10647 (The USB CDC-NCM device class 
(subsys/usb/device_next/class/usbd_cdc_nc ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-55956 (Improper Authorization vulnerability in Apache Tomcat leads to 
securit ...)
-       - tomcat11 <unfixed> (bug #1141337)
+       - tomcat11 11.0.24-1 (bug #1141337)
        - tomcat10 <unfixed> (bug #1141338)
        - tomcat9 9.0.70-2
        NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server 
stack, using that as the fixed version
@@ -34490,7 +34490,7 @@ CVE-2026-55956 (Improper Authorization vulnerability in 
Apache Tomcat leads to s
        NOTE: 
https://github.com/apache/tomcat/commit/9c3b1efb74fd04f77639720af1d48a8f664ad9bb
 (10.1.56)
        NOTE: 
https://github.com/apache/tomcat/commit/a0374c450970760efafbd8806a1db278830ba7bd
 (9.0.119)
 CVE-2026-55955 (Improper Authentication vulnerability in Apache Tomcat allowed 
a repla ...)
-       - tomcat11 <unfixed> (bug #1141337)
+       - tomcat11 11.0.24-1 (bug #1141337)
        - tomcat10 <unfixed> (bug #1141338)
        - tomcat9 9.0.70-2
        NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server 
stack, using that as the fixed version
@@ -34498,7 +34498,7 @@ CVE-2026-55955 (Improper Authentication vulnerability 
in Apache Tomcat allowed a
        NOTE: 
https://github.com/apache/tomcat/commit/3a9ff01d2dfaca651edacbda3260e37b98b540d3
 (10.1.56)
        NOTE: 
https://github.com/apache/tomcat/commit/6a7a432cd7fb4ef358dc12e8da99cf3ab320f3fe
 (9.0.119)
 CVE-2026-55276 (Always-Incorrect Control Flow Implementation vulnerability in 
Apache T ...)
-       - tomcat11 <unfixed> (bug #1141337)
+       - tomcat11 11.0.24-1 (bug #1141337)
        - tomcat10 <unfixed> (bug #1141338)
        - tomcat9 9.0.70-2
        NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server 
stack, using that as the fixed version
@@ -34508,7 +34508,7 @@ CVE-2026-55276 (Always-Incorrect Control Flow 
Implementation vulnerability in Ap
        NOTE: 
https://github.com/apache/tomcat/commit/17daf80a738d66a8e6cad05c5e32c2db81500ce1
 (10.1.56)
        NOTE: 
https://github.com/apache/tomcat/commit/3ca8cae5fd3796b1bd9759e11b0e238161e7a39c
 (9.0.119)
 CVE-2026-53434 (Detection of Error Condition Without Action vulnerability in 
Apache To ...)
-       - tomcat11 <unfixed> (bug #1141337)
+       - tomcat11 11.0.24-1 (bug #1141337)
        - tomcat10 <unfixed> (bug #1141338)
        - tomcat9 9.0.70-2
        NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server 
stack, using that as the fixed version
@@ -34516,7 +34516,7 @@ CVE-2026-53434 (Detection of Error Condition Without 
Action vulnerability in Apa
        NOTE: 
https://github.com/apache/tomcat/commit/feec60d6099727db6f911534f6a0f6926ebab070
 (10.1.56)
        NOTE: 
https://github.com/apache/tomcat/commit/c48ac39c27f4494f8c96b9d56a487253e362d276
 (9.0.119)
 CVE-2026-53404 (Always-Incorrect Control Flow Implementation vulnerability in 
Apache T ...)
-       - tomcat11 <unfixed> (bug #1141337)
+       - tomcat11 11.0.24-1 (bug #1141337)
        - tomcat10 <unfixed> (bug #1141338)
        - tomcat9 9.0.70-2
        NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server 
stack, using that as the fixed version
@@ -34524,7 +34524,7 @@ CVE-2026-53404 (Always-Incorrect Control Flow 
Implementation vulnerability in Ap
        NOTE: 
https://github.com/apache/tomcat/commit/bbb6219fa5ac185060bef7842cee5fb90230ca00
 (10.1.56)
        NOTE: 
https://github.com/apache/tomcat/commit/fe06ae8a71997061596f54189dae1b1b5da75430
 (9.0.119)
 CVE-2026-50229 (Improper Neutralization of Script-Related HTML Tags in a Web 
Page (Bas ...)
-       - tomcat11 <unfixed> (bug #1141337)
+       - tomcat11 11.0.24-1 (bug #1141337)
        - tomcat10 <unfixed> (bug #1141338)
        - tomcat9 9.0.70-2
        NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server 
stack, using that as the fixed version



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9ae64f4acbd63fa928d2aee3d88d9f26af0ff28e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9ae64f4acbd63fa928d2aee3d88d9f26af0ff28e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to