On Thu, Aug 13, 2026 at 1:12 PM Christopher Schultz < [email protected]> wrote:
> The proposed Apache Tomcat 10.1.59 release is now available for > voting. > > All committers and PMC members are kindly requested to provide a vote if > possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are > binding. We welcome non-committer votes or comments on release builds. > > The notable changes compared to 10.1.57[*] are: > > - Add a new attribute to the Context, urlPatternsProvidedInDecodedForm. > This attribute controls whether URLs and URL patterns provided in the > deployment descriptor (web.xml), annotations and/or their programmatic > equivalents are treated as being provided in URL-encoded form (i.e. > using %nn encoding) or in decoded form. The Servlet specification > requires that they are provided in decoded form. However, Tomcat has > historically treated them as if they are provided in encoded form. In > Tomcat 12, they will always be treated as if they are provided in > decoded form. This setting enables migration from encoded form to > decoded form on an application by application basis. This attribute > will be removed in Tomcat 12 where it will effectively be hard-coded > to true. > > - Require every HTTP/2 request to provide an authority (either an > :authority pseudo header or a Host header). > > - Change the default encryptionAlgorithm for the EncryptInterceptor to > AES/GCM/NoPadding. **This is a breaking change for the > EncryptInterceptor.** > > [*] A small bug was found and fixed from the 10.1.58 release, so the > major changes remain the same for 10.1.59. > > For full details, see the change log: > https://nightlies.apache.org/tomcat/tomcat-10.1.x/docs/changelog.html > > Applications that run on Tomcat 9 and earlier will not run on Tomcat 10 > without changes. Java EE applications designed for Tomcat 9 and earlier > may be placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat > will automatically convert them to Jakarta EE and copy them to the > webapps directory. > > It can be obtained from: > https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.1.59/ > > The Maven staging repo is: > https://repository.apache.org/content/repositories/orgapachetomcat-1603 > > The tag is: > https://github.com/apache/tomcat/tree/10.1.59 > > https://github.com/apache/tomcat/commit/08382643a5aaf23bea2915ff88143aedbf8764f5 > > Please reply with a +1 for release or +0/-0/-1 with an explanation. > +1 for release > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > >
