Author: markt
Date: Wed Sep 23 10:01:04 2026
New Revision: 1938456
Log:
Add Tomcat CVE announcement for October releases
Modified:
tomcat/site/trunk/docs/security-10.html
tomcat/site/trunk/docs/security-11.html
tomcat/site/trunk/docs/security-9.html
tomcat/site/trunk/xdocs/security-10.xml
tomcat/site/trunk/xdocs/security-11.xml
tomcat/site/trunk/xdocs/security-9.xml
Modified: tomcat/site/trunk/docs/security-10.html
==============================================================================
--- tomcat/site/trunk/docs/security-10.html Wed Sep 23 08:38:47 2026
(r1938455)
+++ tomcat/site/trunk/docs/security-10.html Wed Sep 23 10:01:04 2026
(r1938456)
@@ -42,7 +42,188 @@
</p>
</div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text">
- <ul><li><a href="#Fixed_in_Apache_Tomcat_10.1.59">Fixed in Apache Tomcat
10.1.59</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.57">Fixed in Apache
Tomcat 10.1.57</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.56">Fixed in
Apache Tomcat 10.1.56</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.55">Fixed in Apache Tomcat
10.1.55</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.54">Fixed in Apache
Tomcat 10.1.54</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.53">Fixed in
Apache Tomcat 10.1.53</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.52">Fixed in Apache Tomcat
10.1.52</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.50">Fixed in Apache
Tomcat 10.1.50</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.47">Fixed in
Apache Tomcat 10.1.47</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.45">Fixed in Apache Tomcat
10.1.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.44">Fixed in Apache
Tomcat 10.1.44</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.43">Fixed in
Apache Tomcat 10.1.43</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.42">Fixed in Apache Tomcat
10.1.42</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.41">Fixed in Apache
Tomcat 10.1.41</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.40">Fixed in
Apache Tomcat 10.1.40</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.39">Fixed in Apache Tomcat
10.1.39</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.35">Fixed in Apache
Tomcat 10.1.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.34">Fixed in
Apache Tomcat 10.1.34</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.33">Fixed in Apache Tomcat
10.1.33</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.31">Fixed in Apache
Tomcat 10.1.31</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.25">Fixed in
Apache Tomcat 10.1.25</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.19">Fixed in Apache Tomcat
10.1.19</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.16">Fixed in Apache
Tomcat 10.1.16</a></li><li><a href="#Fixed_in_Apache_T
omcat_10.1.14">Fixed in Apache Tomcat 10.1.14</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.13">Fixed in Apache Tomcat
10.1.13</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.9">Fixed in Apache
Tomcat 10.1.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.8">Fixed in
Apache Tomcat 10.1.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.6">Fixed
in Apache Tomcat 10.1.6</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.5">Fixed in Apache Tomcat
10.1.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.2">Fixed in Apache
Tomcat 10.1.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.1">Fixed in
Apache Tomcat 10.1.1</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.27">Fixed in Apache Tomcat
10.0.27</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.23">Fixed in Apache
Tomcat 10.0.23</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.0-M17">Fixed
in Apache Tomcat 10.1.0-M17</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.21">Fixed in Apache Tomcat
10.0.21</a></li><li><a href="#
Fixed_in_Apache_Tomcat_10.1.0-M15">Fixed in Apache Tomcat
10.1.0-M15</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.20">Fixed in
Apache Tomcat 10.0.20</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.0-M14">Fixed in Apache Tomcat
10.1.0-M14</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.16">Fixed in
Apache Tomcat 10.0.16</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.0-M10">Fixed in Apache Tomcat
10.1.0-M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.12">Fixed in
Apache Tomcat 10.0.12</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.0-M6">Fixed in Apache Tomcat
10.1.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.7">Fixed in Apache
Tomcat 10.0.7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.6">Fixed in
Apache Tomcat 10.0.6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.5">Fixed
in Apache Tomcat 10.0.5</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.4">Fixed in Apache Tomcat
10.0.4</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.2">Fixed in Apache T
omcat 10.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M10">Fixed in
Apache Tomcat 10.0.0-M10</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.0-M8">Fixed in Apache Tomcat
10.0.0-M8</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M7">Fixed in
Apache Tomcat 10.0.0-M7</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.0-M6">Fixed in Apache Tomcat
10.0.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M5">Fixed in
Apache Tomcat 10.0.0-M5</a></li><li><a
href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in
Tomcat</a></li></ul>
+ <ul><li><a href="#Fixed_in_Apache_Tomcat_10.1.60">Fixed in Apache Tomcat
10.1.60</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.59">Fixed in Apache
Tomcat 10.1.59</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.57">Fixed in
Apache Tomcat 10.1.57</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.56">Fixed in Apache Tomcat
10.1.56</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.55">Fixed in Apache
Tomcat 10.1.55</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.54">Fixed in
Apache Tomcat 10.1.54</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.53">Fixed in Apache Tomcat
10.1.53</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.52">Fixed in Apache
Tomcat 10.1.52</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.50">Fixed in
Apache Tomcat 10.1.50</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.47">Fixed in Apache Tomcat
10.1.47</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.45">Fixed in Apache
Tomcat 10.1.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.44">Fixed in
Apache Tomcat 10.1.44</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.43">Fixed in Apache Tomcat
10.1.43</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.42">Fixed in Apache
Tomcat 10.1.42</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.41">Fixed in
Apache Tomcat 10.1.41</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.40">Fixed in Apache Tomcat
10.1.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.39">Fixed in Apache
Tomcat 10.1.39</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.35">Fixed in
Apache Tomcat 10.1.35</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.34">Fixed in Apache Tomcat
10.1.34</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.33">Fixed in Apache
Tomcat 10.1.33</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.31">Fixed in
Apache Tomcat 10.1.31</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.25">Fixed in Apache Tomcat
10.1.25</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.19">Fixed in Apache
Tomcat 10.1.19</a></li><li><a href="#Fixed_in_Apache_T
omcat_10.1.16">Fixed in Apache Tomcat 10.1.16</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.14">Fixed in Apache Tomcat
10.1.14</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.13">Fixed in Apache
Tomcat 10.1.13</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.9">Fixed in
Apache Tomcat 10.1.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.8">Fixed
in Apache Tomcat 10.1.8</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.6">Fixed in Apache Tomcat
10.1.6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.5">Fixed in Apache
Tomcat 10.1.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.2">Fixed in
Apache Tomcat 10.1.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.1">Fixed
in Apache Tomcat 10.1.1</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.27">Fixed in Apache Tomcat
10.0.27</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.23">Fixed in Apache
Tomcat 10.0.23</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.0-M17">Fixed
in Apache Tomcat 10.1.0-M17</a></li><li><a href="#
Fixed_in_Apache_Tomcat_10.0.21">Fixed in Apache Tomcat 10.0.21</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.0-M15">Fixed in Apache Tomcat
10.1.0-M15</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.20">Fixed in
Apache Tomcat 10.0.20</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.0-M14">Fixed in Apache Tomcat
10.1.0-M14</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.16">Fixed in
Apache Tomcat 10.0.16</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.0-M10">Fixed in Apache Tomcat
10.1.0-M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.12">Fixed in
Apache Tomcat 10.0.12</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.0-M6">Fixed in Apache Tomcat
10.1.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.7">Fixed in Apache
Tomcat 10.0.7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.6">Fixed in
Apache Tomcat 10.0.6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.5">Fixed
in Apache Tomcat 10.0.5</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.4">Fixed in Apache
Tomcat 10.0.4</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.2">Fixed in
Apache Tomcat 10.0.2</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.0-M10">Fixed in Apache Tomcat
10.0.0-M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M8">Fixed in
Apache Tomcat 10.0.0-M8</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.0-M7">Fixed in Apache Tomcat
10.0.0-M7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M6">Fixed in
Apache Tomcat 10.0.0-M6</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.0-M5">Fixed in Apache Tomcat
10.0.0-M5</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a
vulnerability in Tomcat</a></li></ul>
+ </div><h3 id="Fixed_in_Apache_Tomcat_10.1.60"><span
class="pull-right">2026-09-15</span> Fixed in Apache Tomcat 10.1.60</h3><div
class="text">
+
+ <p><strong>Low: WebSocket message smuggling with
+ per-message-deflate</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-87022"
rel="nofollow">CVE-2026-87022</a></p>
+
+ <p>Improper handling of length parameter allows WebSocket message smuggling
+ when per-message-deflate is used.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/567a85515b78d1cd6410a89844b88109fcc2306f">567a8551</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 7 September 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Important: Regression in fix for CVE-2026-41293 can trigger
+ request header mix-up</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86350"
rel="nofollow">CVE-2026-86350</a></p>
+
+ <p>Inconsistent interpretation of HTTP/2 requests caused by a regression in
+ fix for CVE-2026-41293 can trigger request header mix-up.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/259e938d3dedf07f3b24189fd5032adb95b01f2a">259e938d</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 28 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.55 to 10.1.59</p>
+
+ <p><strong>Moderate: Fix for CVE-2026-34500 was incomplete. OCSP checks
+ sometimes soft-fail with FFM even when soft-fail is disabled</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86248"
rel="nofollow">CVE-2026-86248</a></p>
+
+ <p>CLIENT_CERT authentication does not fail as expected for some scenarios
+ when OCSP soft fail is disabled.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/e5191b1e3292681097503f093b5432451ff5aa83">e5191b1e</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 28 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.22 to 10.1.59</p>
+
+ <p><strong>Moderate: WebSocket DoS due to lost asynchronous write
+ timeout</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-79677"
rel="nofollow">CVE-2026-79677</a></p>
+
+ <p>Due to a concurrency bug, an attacker could trigger a denial of service
+ as a result of lost time outs for asynchronous WebSocket writes.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/bb676e53cd0bdcbecfe9650841e99973a7693f7e">bb676e53</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 25 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Low: HTTP/2 DoS via malformed request</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-78437"
rel="nofollow">CVE-2026-78437</a></p>
+
+ <p>A malformed HTTP/2 request could potentially (depends on timing) cause
+ one request from another user to fail.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/4ac5da0906c500f6042844d7f17e9fb174820758">4ac5da09</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 24 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.53 to 10.1.59</p>
+
+ <p><strong>Important: AJP DoS via missing request body</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-78383"
rel="nofollow">CVE-2026-78383</a></p>
+
+ <p>If the end user did not provide a request body, that could pin an AJP
+ processing thread leading to denial of service.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/2ed6d18ebfe4b085ef050dd0a0f4f20aff3bc48d">2ed6d18e</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 24 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Important: DoS via busy wait during WebSocket close</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-77791"
rel="nofollow">CVE-2026-77791</a></p>
+
+ <p>A busy wait during sending of WebSocket close message enabled a DoS
+ attack.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/e896f73c868f66dfb2a93565fda4d13cd5909d2d">e896f73c</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 21 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.8 to 10.1.59</p>
+
+ <p><strong>Low: Stale HPACK emitter injects trailers into recycled pooled
+ Request</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-77762"
rel="nofollow">CVE-2026-77762</a></p>
+
+ <p>A race condition allowed an attacker to inject trailer fields into
+ another HTTP/2 request.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/77d2d59347891eced52b0cb5a979fc33a8a2620c">77d2d593</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 21 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Low: Transfer-Encoding honored for HTTP/1.0 requests</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-77756"
rel="nofollow">CVE-2026-77756</a></p>
+
+ <p>Processing the transfer-encoding header for an HTTP/1.0 request may
allow
+ an attacker to cause one request from another user to fail when Tomcat
is
+ located behind a reverse proxy.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/bf44bee23d97fbb1a64cbbbb213ff2b6506d26c4">bf44bee2</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 20 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Important: Bypass of security constraints for WebSocket
+ endpoints</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-76183"
rel="nofollow">CVE-2026-76183</a></p>
+
+ <p>Request paths were incorrectly parsed as endpoint templates allowing the
+ bypass of security constraints for WebSocket endpoints.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/5b48790abd13d94c2bd351027a39a671916b5ddf">5b48790a</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 17 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Low: Cross-context authentication mix-up with Jakarta
+ Authentication configured</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-75973"
rel="nofollow">CVE-2026-75973</a></p>
+
+ <p>When Jakarta Authentication was configured with SimpleAuthConfigProvider
+ as the default provider and multiple web application used that provider,
+ the realm for the first web application to authenticate a request would
+ be used for all web applications.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/f62c65768fdaa300e22e64ffa7b5118dce0571a1">f62c6576</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 13 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Moderate: OpenSSL and OpenSSL-FFM TLS implementations ignore
CRLs
+ when certificate uses a keystore</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73581"
rel="nofollow">CVE-2026-73581</a></p>
+
+ <p>Both the OpenSSL and OpenSSL-FFM TLS implementations ignored CRLs when
+ certificate used a keystore.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/6907d47ea2d4c3f13ef9f65b0c51ff2fd485c252">6907d47e</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 11 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
</div><h3 id="Fixed_in_Apache_Tomcat_10.1.59"><span
class="pull-right">2026-08-20</span> Fixed in Apache Tomcat 10.1.59</h3><div
class="text">
<p><i>Note: The issues below were fixed in Apache Tomcat 10.1.58 but the
Modified: tomcat/site/trunk/docs/security-11.html
==============================================================================
--- tomcat/site/trunk/docs/security-11.html Wed Sep 23 08:38:47 2026
(r1938455)
+++ tomcat/site/trunk/docs/security-11.html Wed Sep 23 10:01:04 2026
(r1938456)
@@ -36,7 +36,188 @@
</p>
</div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text">
- <ul><li><a href="#Fixed_in_Apache_Tomcat_11.0.25">Fixed in Apache Tomcat
11.0.25</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.24">Fixed in Apache
Tomcat 11.0.24</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.23">Fixed in
Apache Tomcat 11.0.23</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.22">Fixed in Apache Tomcat
11.0.22</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.21">Fixed in Apache
Tomcat 11.0.21</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.20">Fixed in
Apache Tomcat 11.0.20</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.18">Fixed in Apache Tomcat
11.0.18</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.15">Fixed in Apache
Tomcat 11.0.15</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.12">Fixed in
Apache Tomcat 11.0.12</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.11">Fixed in Apache Tomcat
11.0.11</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.10">Fixed in Apache
Tomcat 11.0.10</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.9">Fixed in
Apache Tomcat 11.0.9</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.8">Fixed in Apache Tomcat
11.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.7">Fixed in Apache
Tomcat 11.0.7</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.6">Fixed in
Apache Tomcat 11.0.6</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.5">Fixed
in Apache Tomcat 11.0.5</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.3">Fixed in Apache Tomcat
11.0.3</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.2">Fixed in Apache
Tomcat 11.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.1">Fixed in
Apache Tomcat 11.0.1</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.0">Fixed
in Apache Tomcat 11.0.0</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.0-M21">Fixed in Apache Tomcat
11.0.0-M21</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.0-M17">Fixed in
Apache Tomcat 11.0.0-M17</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.0-M12">Fixed in Apache Tomcat
11.0.0-M12</a></li><li><a href="#Fixed_in_Apache_T
omcat_11.0.0-M11">Fixed in Apache Tomcat 11.0.0-M11</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.0-M6">Fixed in Apache Tomcat
11.0.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.0-M5">Fixed in
Apache Tomcat 11.0.0-M5</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.0-M3">Fixed in Apache Tomcat
11.0.0-M3</a></li></ul>
+ <ul><li><a href="#Fixed_in_Apache_Tomcat_11.0.26">Fixed in Apache Tomcat
11.0.26</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.25">Fixed in Apache
Tomcat 11.0.25</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.24">Fixed in
Apache Tomcat 11.0.24</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.23">Fixed in Apache Tomcat
11.0.23</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.22">Fixed in Apache
Tomcat 11.0.22</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.21">Fixed in
Apache Tomcat 11.0.21</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.20">Fixed in Apache Tomcat
11.0.20</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.18">Fixed in Apache
Tomcat 11.0.18</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.15">Fixed in
Apache Tomcat 11.0.15</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.12">Fixed in Apache Tomcat
11.0.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.11">Fixed in Apache
Tomcat 11.0.11</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.10">Fixed in
Apache Tomcat 11.0.10</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.9">Fixed in Apache Tomcat
11.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.8">Fixed in Apache
Tomcat 11.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.7">Fixed in
Apache Tomcat 11.0.7</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.6">Fixed
in Apache Tomcat 11.0.6</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.5">Fixed in Apache Tomcat
11.0.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.3">Fixed in Apache
Tomcat 11.0.3</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.2">Fixed in
Apache Tomcat 11.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.1">Fixed
in Apache Tomcat 11.0.1</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.0">Fixed in Apache Tomcat
11.0.0</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.0-M21">Fixed in Apache
Tomcat 11.0.0-M21</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.0-M17">Fixed in Apache Tomcat
11.0.0-M17</a></li><li><a href="#Fixed_in_Apache_Tomcat_
11.0.0-M12">Fixed in Apache Tomcat 11.0.0-M12</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.0-M11">Fixed in Apache Tomcat
11.0.0-M11</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.0-M6">Fixed in
Apache Tomcat 11.0.0-M6</a></li><li><a
href="#Fixed_in_Apache_Tomcat_11.0.0-M5">Fixed in Apache Tomcat
11.0.0-M5</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.0-M3">Fixed in
Apache Tomcat 11.0.0-M3</a></li></ul>
+ </div><h3 id="Fixed_in_Apache_Tomcat_11.0.26"><span
class="pull-right">2026-09-15</span> Fixed in Apache Tomcat 11.0.26</h3><div
class="text">
+
+ <p><strong>Low: WebSocket message smuggling with
+ per-message-deflate</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-87022"
rel="nofollow">CVE-2026-87022</a></p>
+
+ <p>Improper handling of length parameter allows WebSocket message smuggling
+ when per-message-deflate is used.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/4fef25fe2ab7509e697af093280b9daadb515615">4fef25fe</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 7 September 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Important: Regression in fix for CVE-2026-41293 can trigger
+ request header mix-up</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86350"
rel="nofollow">CVE-2026-86350</a></p>
+
+ <p>Inconsistent interpretation of HTTP/2 requests caused by a regression in
+ fix for CVE-2026-41293 can trigger request header mix-up.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/192bc74996e1ad35d79118f750574d366bd43cea">192bc749</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 28 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.22 to 11.0.25</p>
+
+ <p><strong>Moderate: Fix for CVE-2026-34500 was incomplete. OCSP checks
+ sometimes soft-fail with FFM even when soft-fail is disabled</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86248"
rel="nofollow">CVE-2026-86248</a></p>
+
+ <p>CLIENT_CERT authentication does not fail as expected for some scenarios
+ when OCSP soft fail is disabled.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/9aab76056e7470bcc8ca9a20b33b6558b1046da2">9aab7605</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 28 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M14 to 11.0.25</p>
+
+ <p><strong>Moderate: WebSocket DoS due to lost asynchronous write
+ timeout</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-79677"
rel="nofollow">CVE-2026-79677</a></p>
+
+ <p>Due to a concurrency bug, an attacker could trigger a denial of service
+ as a result of lost time outs for asynchronous WebSocket writes.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/7ab11d10de79a7a2226f41c8289871db69c6ca9c">7ab11d10</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 25 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Low: HTTP/2 DoS via malformed request</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-78437"
rel="nofollow">CVE-2026-78437</a></p>
+
+ <p>A malformed HTTP/2 request could potentially (depends on timing) cause
+ one request from another user to fail.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/70579060454a203977b5696ece71e7cbd6ee9bde">70579060</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 24 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.19 to 11.0.25</p>
+
+ <p><strong>Important: AJP DoS via missing request body</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-78383"
rel="nofollow">CVE-2026-78383</a></p>
+
+ <p>If the end user did not provide a request body, that could pin an AJP
+ processing thread leading to denial of service.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/6dabd4303095785183ede57f6d162c542955a5a8">6dabd430</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 24 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Important: DoS via busy wait during WebSocket close</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-77791"
rel="nofollow">CVE-2026-77791</a></p>
+
+ <p>A busy wait during sending of WebSocket close message enabled a DoS
+ attack.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/ce291bbc65393e3bfbec2a8d23fcee0106a1ade9">ce291bbc</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 21 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M5 to 11.0.25</p>
+
+ <p><strong>Low: Stale HPACK emitter injects trailers into recycled pooled
+ Request</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-77762"
rel="nofollow">CVE-2026-77762</a></p>
+
+ <p>A race condition allowed an attacker to inject trailer fields into
+ another HTTP/2 request.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/fd309997dfd0d351b26959a8afd7bffec33dd0de">fd309997</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 21 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Low: Transfer-Encoding honored for HTTP/1.0 requests</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-77756"
rel="nofollow">CVE-2026-77756</a></p>
+
+ <p>Processing the transfer-encoding header for an HTTP/1.0 request may
allow
+ an attacker to cause one request from another user to fail when Tomcat
is
+ located behind a reverse proxy.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/1ad63de866a6e7007304ebe5165f72e65ece32b6">1ad63de8</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 20 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Important: Bypass of security constraints for WebSocket
+ endpoints</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-76183"
rel="nofollow">CVE-2026-76183</a></p>
+
+ <p>Request paths were incorrectly parsed as endpoint templates allowing the
+ bypass of security constraints for WebSocket endpoints.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/e182d86b7d4cc19ec4c24c38f37acc004404fe8e">e182d86b</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 17 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Low: Cross-context authentication mix-up with Jakarta
+ Authentication configured</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-75973"
rel="nofollow">CVE-2026-75973</a></p>
+
+ <p>When Jakarta Authentication was configured with SimpleAuthConfigProvider
+ as the default provider and multiple web application used that provider,
+ the realm for the first web application to authenticate a request would
+ be used for all web applications.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/2585fc798f24f0b8811fd20ad9b4e8affb6f69a6">2585fc79</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 13 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Moderate: OpenSSL and OpenSSL-FFM TLS implementations ignore
CRLs
+ when certificate uses a keystore</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73581"
rel="nofollow">CVE-2026-73581</a></p>
+
+ <p>Both the OpenSSL and OpenSSL-FFM TLS implementations ignored CRLs when
+ certificate used a keystore.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/15a76156ced9f6a6306ef7d6f2e343034231a2de">15a76156</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 11 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
</div><h3 id="Fixed_in_Apache_Tomcat_11.0.25"><span
class="pull-right">2026-08-18</span> Fixed in Apache Tomcat 11.0.25</h3><div
class="text">
<p><strong>Low: Authenticated WebSocket session survives end of HTTP
Modified: tomcat/site/trunk/docs/security-9.html
==============================================================================
--- tomcat/site/trunk/docs/security-9.html Wed Sep 23 08:38:47 2026
(r1938455)
+++ tomcat/site/trunk/docs/security-9.html Wed Sep 23 10:01:04 2026
(r1938456)
@@ -36,7 +36,188 @@
</p>
</div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text">
- <ul><li><a href="#Fixed_in_Apache_Tomcat_9.0.121">Fixed in Apache Tomcat
9.0.121</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.120">Fixed in Apache
Tomcat 9.0.120</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.119">Fixed in
Apache Tomcat 9.0.119</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.118">Fixed in Apache Tomcat
9.0.118</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.117">Fixed in Apache
Tomcat 9.0.117</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.116">Fixed in
Apache Tomcat 9.0.116</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.115">Fixed in Apache Tomcat
9.0.115</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.113">Fixed in Apache
Tomcat 9.0.113</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.110">Fixed in
Apache Tomcat 9.0.110</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.109">Fixed in Apache Tomcat
9.0.109</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.108">Fixed in Apache
Tomcat 9.0.108</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.107">Fixed in
Apache Tomcat 9.0.107</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.106">Fixed in Apache Tomcat
9.0.106</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.105">Fixed in Apache
Tomcat 9.0.105</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.104">Fixed in
Apache Tomcat 9.0.104</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.102">Fixed in Apache Tomcat
9.0.102</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.99">Fixed in Apache
Tomcat 9.0.99</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.98">Fixed in
Apache Tomcat 9.0.98</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.97">Fixed
in Apache Tomcat 9.0.97</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.96">Fixed in Apache Tomcat
9.0.96</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.90">Fixed in Apache
Tomcat 9.0.90</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.86">Fixed in
Apache Tomcat 9.0.86</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.83">Fixed
in Apache Tomcat 9.0.83</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.81">
Fixed in Apache Tomcat 9.0.81</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.80">Fixed in Apache Tomcat
9.0.80</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.75">Fixed in Apache
Tomcat 9.0.75</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.74">Fixed in
Apache Tomcat 9.0.74</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.72">Fixed
in Apache Tomcat 9.0.72</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.71">Fixed in Apache Tomcat
9.0.71</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.69">Fixed in Apache
Tomcat 9.0.69</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.68">Fixed in
Apache Tomcat 9.0.68</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.65">Fixed
in Apache Tomcat 9.0.65</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.63">Fixed in Apache Tomcat
9.0.63</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.62">Fixed in Apache
Tomcat 9.0.62</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.58">Fixed in
Apache Tomcat 9.0.58</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.54">F
ixed in Apache Tomcat 9.0.54</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.48">Fixed in Apache Tomcat
9.0.48</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.46">Fixed in Apache
Tomcat 9.0.46</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.45">Fixed in
Apache Tomcat 9.0.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.44">Fixed
in Apache Tomcat 9.0.44</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.43">Fixed in Apache Tomcat
9.0.43</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.40">Fixed in Apache
Tomcat 9.0.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.38">Fixed in
Apache Tomcat 9.0.38</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.37">Fixed
in Apache Tomcat 9.0.37</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.36">Fixed in Apache Tomcat
9.0.36</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.35">Fixed in Apache
Tomcat 9.0.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.31">Fixed in
Apache Tomcat 9.0.31</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.30">Fi
xed in Apache Tomcat 9.0.30</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.29">Fixed in Apache Tomcat
9.0.29</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.21">Fixed in Apache
Tomcat 9.0.21</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.20">Fixed in
Apache Tomcat 9.0.20</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.19">Fixed
in Apache Tomcat 9.0.19</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.16">Fixed in Apache Tomcat
9.0.16</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.12">Fixed in Apache
Tomcat 9.0.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.10">Fixed in
Apache Tomcat 9.0.10</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.9">Fixed
in Apache Tomcat 9.0.9</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.8">Fixed in Apache Tomcat
9.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.5">Fixed in Apache
Tomcat 9.0.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.2">Fixed in
Apache Tomcat 9.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.1">Fixed
in Apa
che Tomcat 9.0.1</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M22">Fixed
in Apache Tomcat 9.0.0.M22</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M21">Fixed in Apache Tomcat
9.0.0.M21</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M19">Fixed in
Apache Tomcat 9.0.0.M19</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M18">Fixed in Apache Tomcat
9.0.0.M18</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M17">Fixed in
Apache Tomcat 9.0.0.M17</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M15">Fixed in Apache Tomcat
9.0.0.M15</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M13">Fixed in
Apache Tomcat 9.0.0.M13</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M10">Fixed in Apache Tomcat
9.0.0.M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M8">Fixed in
Apache Tomcat 9.0.0.M8</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M3">Fixed in Apache Tomcat
9.0.0.M3</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a
vulnerability in Tomcat</a></li></u
l>
+ <ul><li><a href="#Fixed_in_Apache_Tomcat_9.0.122">Fixed in Apache Tomcat
9.0.122</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.121">Fixed in Apache
Tomcat 9.0.121</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.120">Fixed in
Apache Tomcat 9.0.120</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.119">Fixed in Apache Tomcat
9.0.119</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.118">Fixed in Apache
Tomcat 9.0.118</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.117">Fixed in
Apache Tomcat 9.0.117</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.116">Fixed in Apache Tomcat
9.0.116</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.115">Fixed in Apache
Tomcat 9.0.115</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.113">Fixed in
Apache Tomcat 9.0.113</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.110">Fixed in Apache Tomcat
9.0.110</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.109">Fixed in Apache
Tomcat 9.0.109</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.108">Fixed in
Apache Tomcat 9.0.108</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.107">Fixed in Apache Tomcat
9.0.107</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.106">Fixed in Apache
Tomcat 9.0.106</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.105">Fixed in
Apache Tomcat 9.0.105</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.104">Fixed in Apache Tomcat
9.0.104</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.102">Fixed in Apache
Tomcat 9.0.102</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.99">Fixed in
Apache Tomcat 9.0.99</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.98">Fixed
in Apache Tomcat 9.0.98</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.97">Fixed in Apache Tomcat
9.0.97</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.96">Fixed in Apache
Tomcat 9.0.96</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.90">Fixed in
Apache Tomcat 9.0.90</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.86">Fixed
in Apache Tomcat 9.0.86</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.83
">Fixed in Apache Tomcat 9.0.83</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.81">Fixed in Apache Tomcat
9.0.81</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.80">Fixed in Apache
Tomcat 9.0.80</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.75">Fixed in
Apache Tomcat 9.0.75</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.74">Fixed
in Apache Tomcat 9.0.74</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.72">Fixed in Apache Tomcat
9.0.72</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.71">Fixed in Apache
Tomcat 9.0.71</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.69">Fixed in
Apache Tomcat 9.0.69</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.68">Fixed
in Apache Tomcat 9.0.68</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.65">Fixed in Apache Tomcat
9.0.65</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.63">Fixed in Apache
Tomcat 9.0.63</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.62">Fixed in
Apache Tomcat 9.0.62</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.58"
>Fixed in Apache Tomcat 9.0.58</a></li><li><a
>href="#Fixed_in_Apache_Tomcat_9.0.54">Fixed in Apache Tomcat
>9.0.54</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.48">Fixed in Apache
>Tomcat 9.0.48</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.46">Fixed in
>Apache Tomcat 9.0.46</a></li><li><a
>href="#Fixed_in_Apache_Tomcat_9.0.45">Fixed in Apache Tomcat
>9.0.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.44">Fixed in Apache
>Tomcat 9.0.44</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.43">Fixed in
>Apache Tomcat 9.0.43</a></li><li><a
>href="#Fixed_in_Apache_Tomcat_9.0.40">Fixed in Apache Tomcat
>9.0.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.38">Fixed in Apache
>Tomcat 9.0.38</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.37">Fixed in
>Apache Tomcat 9.0.37</a></li><li><a
>href="#Fixed_in_Apache_Tomcat_9.0.36">Fixed in Apache Tomcat
>9.0.36</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.35">Fixed in Apache
>Tomcat 9.0.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.31">
Fixed in Apache Tomcat 9.0.31</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.30">Fixed in Apache Tomcat
9.0.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.29">Fixed in Apache
Tomcat 9.0.29</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.21">Fixed in
Apache Tomcat 9.0.21</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.20">Fixed
in Apache Tomcat 9.0.20</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.19">Fixed in Apache Tomcat
9.0.19</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.16">Fixed in Apache
Tomcat 9.0.16</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.12">Fixed in
Apache Tomcat 9.0.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.10">Fixed
in Apache Tomcat 9.0.10</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.9">Fixed in Apache Tomcat
9.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.8">Fixed in Apache
Tomcat 9.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.5">Fixed in
Apache Tomcat 9.0.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.2">Fixed in
Apache Tomcat 9.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.1">Fixed
in Apache Tomcat 9.0.1</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M22">Fixed in Apache Tomcat
9.0.0.M22</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M21">Fixed in
Apache Tomcat 9.0.0.M21</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M19">Fixed in Apache Tomcat
9.0.0.M19</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M18">Fixed in
Apache Tomcat 9.0.0.M18</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M17">Fixed in Apache Tomcat
9.0.0.M17</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M15">Fixed in
Apache Tomcat 9.0.0.M15</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M13">Fixed in Apache Tomcat
9.0.0.M13</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M10">Fixed in
Apache Tomcat 9.0.0.M10</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M8">Fixed in Apache Tomcat
9.0.0.M8</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M3">Fixed in Apache
Tomcat 9.0.0.M3</a></li><
li><a href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in
Tomcat</a></li></ul>
+ </div><h3 id="Fixed_in_Apache_Tomcat_9.0.122"><span
class="pull-right">2026-09-15</span> Fixed in Apache Tomcat 9.0.122</h3><div
class="text">
+
+ <p><strong>Low: WebSocket message smuggling with
+ per-message-deflate</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-87022"
rel="nofollow">CVE-2026-87022</a></p>
+
+ <p>Improper handling of length parameter allows WebSocket message smuggling
+ when per-message-deflate is used.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/959a52a227cc35101b92dae35b722546167594d6">959a52a2</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 7 September 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.0.M1 to 9.0.121</p>
+
+ <p><strong>Important: Regression in fix for CVE-2026-41293 can trigger
+ request header mix-up</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86350"
rel="nofollow">CVE-2026-86350</a></p>
+
+ <p>Inconsistent interpretation of HTTP/2 requests caused by a regression in
+ fix for CVE-2026-41293 can trigger request header mix-up.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/5adadc4ef413d5050f664d40800bbff74bd5d5ed">5adadc4e</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 28 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.118 to 9.0.121</p>
+
+ <p><strong>Moderate: Fix for CVE-2026-34500 was incomplete. OCSP checks
+ sometimes soft-fail with FFM even when soft-fail is disabled</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86248"
rel="nofollow">CVE-2026-86248</a></p>
+
+ <p>CLIENT_CERT authentication does not fail as expected for some scenarios
+ when OCSP soft fail is disabled.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/fc41d82e0e383e4d6e88ad321d245dafdc17d26d">fc41d82e</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 28 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.92 to 9.0.121</p>
+
+ <p><strong>Moderate: WebSocket DoS due to lost asynchronous write
+ timeout</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-79677"
rel="nofollow">CVE-2026-79677</a></p>
+
+ <p>Due to a concurrency bug, an attacker could trigger a denial of service
+ as a result of lost time outs for asynchronous WebSocket writes.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/c8fa5430233bca5b209c593dd446f88fda9d543e">c8fa5430</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 25 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.0.M1 to 9.0.121</p>
+
+ <p><strong>Low: HTTP/2 DoS via malformed request</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-78437"
rel="nofollow">CVE-2026-78437</a></p>
+
+ <p>A malformed HTTP/2 request could potentially (depends on timing) cause
+ one request from another user to fail.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/a28c35055ab11d35929ad564beb1a23a67b39546">a28c3505</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 24 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.116 to 9.0.121</p>
+
+ <p><strong>Important: AJP DoS via missing request body</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-78383"
rel="nofollow">CVE-2026-78383</a></p>
+
+ <p>If the end user did not provide a request body, that could pin an AJP
+ processing thread leading to denial of service.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/265bdc0a58b1447ff5d8f8b96ea81de58cb74c8c">265bdc0a</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 24 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.0.M1 to 9.0.121</p>
+
+ <p><strong>Important: DoS via busy wait during WebSocket close</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-77791"
rel="nofollow">CVE-2026-77791</a></p>
+
+ <p>A busy wait during sending of WebSocket close message enabled a DoS
+ attack.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/7a5945f1de1d3310214234dfbbd7c569af52d058">7a5945f1</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 21 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.74 to 9.0.121</p>
+
+ <p><strong>Low: Stale HPACK emitter injects trailers into recycled pooled
+ Request</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-77762"
rel="nofollow">CVE-2026-77762</a></p>
+
+ <p>A race condition allowed an attacker to inject trailer fields into
+ another HTTP/2 request.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/71f27c2e84810930beda468b5ba732dcd0ef2652">71f27c2e</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 21 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.39 to 9.0.121</p>
+
+ <p><strong>Low: Transfer-Encoding honored for HTTP/1.0 requests</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-77756"
rel="nofollow">CVE-2026-77756</a></p>
+
+ <p>Processing the transfer-encoding header for an HTTP/1.0 request may
allow
+ an attacker to cause one request from another user to fail when Tomcat
is
+ located behind a reverse proxy.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/e590588ab7649c93d49b0eb7b3152700a977880d">e590588a</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 20 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.47 to 9.0.121</p>
+
+ <p><strong>Important: Bypass of security constraints for WebSocket
+ endpoints</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-76183"
rel="nofollow">CVE-2026-76183</a></p>
+
+ <p>Request paths were incorrectly parsed as endpoint templates allowing the
+ bypass of security constraints for WebSocket endpoints.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/a93a60a33f4cc202542eb6a0b87b7142d7db311c">a93a60a3</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 17 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.0.M1 to 9.0.121</p>
+
+ <p><strong>Low: Cross-context authentication mix-up with Jakarta
+ Authentication configured</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-75973"
rel="nofollow">CVE-2026-75973</a></p>
+
+ <p>When Jakarta Authentication was configured with SimpleAuthConfigProvider
+ as the default provider and multiple web application used that provider,
+ the realm for the first web application to authenticate a request would
+ be used for all web applications.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/043115414a39127cad015e9d285296e59c18bb41">04311541</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 13 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.0.M4 to 9.0.121</p>
+
+ <p><strong>Moderate: OpenSSL and OpenSSL-FFM TLS implementations ignore
CRLs
+ when certificate uses a keystore</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73581"
rel="nofollow">CVE-2026-73581</a></p>
+
+ <p>Both the OpenSSL and OpenSSL-FFM TLS implementations ignored CRLs when
+ certificate used a keystore.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/2dce8f26b3ba6a89c8f172b94fa41a5fa2dcc361">2dce8f26</a>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 11 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.0.M1 to 9.0.121</p>
+
</div><h3 id="Fixed_in_Apache_Tomcat_9.0.121"><span
class="pull-right">2026-08-18</span> Fixed in Apache Tomcat 9.0.121</h3><div
class="text">
<p><strong>Low: Authenticated WebSocket session survives end of HTTP
Modified: tomcat/site/trunk/xdocs/security-10.xml
==============================================================================
--- tomcat/site/trunk/xdocs/security-10.xml Wed Sep 23 08:38:47 2026
(r1938455)
+++ tomcat/site/trunk/xdocs/security-10.xml Wed Sep 23 10:01:04 2026
(r1938456)
@@ -56,6 +56,189 @@
<toc/>
</section>
+ <section name="Fixed in Apache Tomcat 10.1.60" rtext="2026-09-15">
+
+ <p><strong>Low: WebSocket message smuggling with
+ per-message-deflate</strong>
+ <cve>CVE-2026-87022</cve></p>
+
+ <p>Improper handling of length parameter allows WebSocket message smuggling
+ when per-message-deflate is used.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="567a85515b78d1cd6410a89844b88109fcc2306f"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 7 September 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Important: Regression in fix for CVE-2026-41293 can trigger
+ request header mix-up</strong>
+ <cve>CVE-2026-86350</cve></p>
+
+ <p>Inconsistent interpretation of HTTP/2 requests caused by a regression in
+ fix for CVE-2026-41293 can trigger request header mix-up.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="259e938d3dedf07f3b24189fd5032adb95b01f2a"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 28 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.55 to 10.1.59</p>
+
+ <p><strong>Moderate: Fix for CVE-2026-34500 was incomplete. OCSP checks
+ sometimes soft-fail with FFM even when soft-fail is disabled</strong>
+ <cve>CVE-2026-86248</cve></p>
+
+ <p>CLIENT_CERT authentication does not fail as expected for some scenarios
+ when OCSP soft fail is disabled.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="e5191b1e3292681097503f093b5432451ff5aa83"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 28 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.22 to 10.1.59</p>
+
+ <p><strong>Moderate: WebSocket DoS due to lost asynchronous write
+ timeout</strong>
+ <cve>CVE-2026-79677</cve></p>
+
+ <p>Due to a concurrency bug, an attacker could trigger a denial of service
+ as a result of lost time outs for asynchronous WebSocket writes.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="bb676e53cd0bdcbecfe9650841e99973a7693f7e"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 25 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Low: HTTP/2 DoS via malformed request</strong>
+ <cve>CVE-2026-78437</cve></p>
+
+ <p>A malformed HTTP/2 request could potentially (depends on timing) cause
+ one request from another user to fail.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="4ac5da0906c500f6042844d7f17e9fb174820758"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 24 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.53 to 10.1.59</p>
+
+ <p><strong>Important: AJP DoS via missing request body</strong>
+ <cve>CVE-2026-78383</cve></p>
+
+ <p>If the end user did not provide a request body, that could pin an AJP
+ processing thread leading to denial of service.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="2ed6d18ebfe4b085ef050dd0a0f4f20aff3bc48d"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 24 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Important: DoS via busy wait during WebSocket close</strong>
+ <cve>CVE-2026-77791</cve></p>
+
+ <p>A busy wait during sending of WebSocket close message enabled a DoS
+ attack.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="e896f73c868f66dfb2a93565fda4d13cd5909d2d"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 21 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.8 to 10.1.59</p>
+
+ <p><strong>Low: Stale HPACK emitter injects trailers into recycled pooled
+ Request</strong>
+ <cve>CVE-2026-77762</cve></p>
+
+ <p>A race condition allowed an attacker to inject trailer fields into
+ another HTTP/2 request.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="77d2d59347891eced52b0cb5a979fc33a8a2620c"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 21 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Low: Transfer-Encoding honored for HTTP/1.0 requests</strong>
+ <cve>CVE-2026-77756</cve></p>
+
+ <p>Processing the transfer-encoding header for an HTTP/1.0 request may
allow
+ an attacker to cause one request from another user to fail when Tomcat
is
+ located behind a reverse proxy.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="bf44bee23d97fbb1a64cbbbb213ff2b6506d26c4"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 20 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Important: Bypass of security constraints for WebSocket
+ endpoints</strong>
+ <cve>CVE-2026-76183</cve></p>
+
+ <p>Request paths were incorrectly parsed as endpoint templates allowing the
+ bypass of security constraints for WebSocket endpoints.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="5b48790abd13d94c2bd351027a39a671916b5ddf"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 17 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Low: Cross-context authentication mix-up with Jakarta
+ Authentication configured</strong>
+ <cve>CVE-2026-75973</cve></p>
+
+ <p>When Jakarta Authentication was configured with SimpleAuthConfigProvider
+ as the default provider and multiple web application used that provider,
+ the realm for the first web application to authenticate a request would
+ be used for all web applications.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="f62c65768fdaa300e22e64ffa7b5118dce0571a1"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 13 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ <p><strong>Moderate: OpenSSL and OpenSSL-FFM TLS implementations ignore
CRLs
+ when certificate uses a keystore</strong>
+ <cve>CVE-2026-73581</cve></p>
+
+ <p>Both the OpenSSL and OpenSSL-FFM TLS implementations ignored CRLs when
+ certificate used a keystore.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="6907d47ea2d4c3f13ef9f65b0c51ff2fd485c252"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 11 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.59</p>
+
+ </section>
+
<section name="Fixed in Apache Tomcat 10.1.59" rtext="2026-08-20">
<p><i>Note: The issues below were fixed in Apache Tomcat 10.1.58 but the
Modified: tomcat/site/trunk/xdocs/security-11.xml
==============================================================================
--- tomcat/site/trunk/xdocs/security-11.xml Wed Sep 23 08:38:47 2026
(r1938455)
+++ tomcat/site/trunk/xdocs/security-11.xml Wed Sep 23 10:01:04 2026
(r1938456)
@@ -50,6 +50,189 @@
<toc/>
</section>
+ <section name="Fixed in Apache Tomcat 11.0.26" rtext="2026-09-15">
+
+ <p><strong>Low: WebSocket message smuggling with
+ per-message-deflate</strong>
+ <cve>CVE-2026-87022</cve></p>
+
+ <p>Improper handling of length parameter allows WebSocket message smuggling
+ when per-message-deflate is used.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="4fef25fe2ab7509e697af093280b9daadb515615"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 7 September 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Important: Regression in fix for CVE-2026-41293 can trigger
+ request header mix-up</strong>
+ <cve>CVE-2026-86350</cve></p>
+
+ <p>Inconsistent interpretation of HTTP/2 requests caused by a regression in
+ fix for CVE-2026-41293 can trigger request header mix-up.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="192bc74996e1ad35d79118f750574d366bd43cea"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 28 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.22 to 11.0.25</p>
+
+ <p><strong>Moderate: Fix for CVE-2026-34500 was incomplete. OCSP checks
+ sometimes soft-fail with FFM even when soft-fail is disabled</strong>
+ <cve>CVE-2026-86248</cve></p>
+
+ <p>CLIENT_CERT authentication does not fail as expected for some scenarios
+ when OCSP soft fail is disabled.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="9aab76056e7470bcc8ca9a20b33b6558b1046da2"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 28 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M14 to 11.0.25</p>
+
+ <p><strong>Moderate: WebSocket DoS due to lost asynchronous write
+ timeout</strong>
+ <cve>CVE-2026-79677</cve></p>
+
+ <p>Due to a concurrency bug, an attacker could trigger a denial of service
+ as a result of lost time outs for asynchronous WebSocket writes.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="7ab11d10de79a7a2226f41c8289871db69c6ca9c"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 25 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Low: HTTP/2 DoS via malformed request</strong>
+ <cve>CVE-2026-78437</cve></p>
+
+ <p>A malformed HTTP/2 request could potentially (depends on timing) cause
+ one request from another user to fail.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="70579060454a203977b5696ece71e7cbd6ee9bde"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 24 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.19 to 11.0.25</p>
+
+ <p><strong>Important: AJP DoS via missing request body</strong>
+ <cve>CVE-2026-78383</cve></p>
+
+ <p>If the end user did not provide a request body, that could pin an AJP
+ processing thread leading to denial of service.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="6dabd4303095785183ede57f6d162c542955a5a8"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 24 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Important: DoS via busy wait during WebSocket close</strong>
+ <cve>CVE-2026-77791</cve></p>
+
+ <p>A busy wait during sending of WebSocket close message enabled a DoS
+ attack.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="ce291bbc65393e3bfbec2a8d23fcee0106a1ade9"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 21 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M5 to 11.0.25</p>
+
+ <p><strong>Low: Stale HPACK emitter injects trailers into recycled pooled
+ Request</strong>
+ <cve>CVE-2026-77762</cve></p>
+
+ <p>A race condition allowed an attacker to inject trailer fields into
+ another HTTP/2 request.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="fd309997dfd0d351b26959a8afd7bffec33dd0de"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 21 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Low: Transfer-Encoding honored for HTTP/1.0 requests</strong>
+ <cve>CVE-2026-77756</cve></p>
+
+ <p>Processing the transfer-encoding header for an HTTP/1.0 request may
allow
+ an attacker to cause one request from another user to fail when Tomcat
is
+ located behind a reverse proxy.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="1ad63de866a6e7007304ebe5165f72e65ece32b6"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 20 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Important: Bypass of security constraints for WebSocket
+ endpoints</strong>
+ <cve>CVE-2026-76183</cve></p>
+
+ <p>Request paths were incorrectly parsed as endpoint templates allowing the
+ bypass of security constraints for WebSocket endpoints.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="e182d86b7d4cc19ec4c24c38f37acc004404fe8e"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 17 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Low: Cross-context authentication mix-up with Jakarta
+ Authentication configured</strong>
+ <cve>CVE-2026-75973</cve></p>
+
+ <p>When Jakarta Authentication was configured with SimpleAuthConfigProvider
+ as the default provider and multiple web application used that provider,
+ the realm for the first web application to authenticate a request would
+ be used for all web applications.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="2585fc798f24f0b8811fd20ad9b4e8affb6f69a6"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 13 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ <p><strong>Moderate: OpenSSL and OpenSSL-FFM TLS implementations ignore
CRLs
+ when certificate uses a keystore</strong>
+ <cve>CVE-2026-73581</cve></p>
+
+ <p>Both the OpenSSL and OpenSSL-FFM TLS implementations ignored CRLs when
+ certificate used a keystore.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="15a76156ced9f6a6306ef7d6f2e343034231a2de"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 11 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 11.0.0-M1 to 11.0.25</p>
+
+ </section>
+
<section name="Fixed in Apache Tomcat 11.0.25" rtext="2026-08-18">
<p><strong>Low: Authenticated WebSocket session survives end of HTTP
Modified: tomcat/site/trunk/xdocs/security-9.xml
==============================================================================
--- tomcat/site/trunk/xdocs/security-9.xml Wed Sep 23 08:38:47 2026
(r1938455)
+++ tomcat/site/trunk/xdocs/security-9.xml Wed Sep 23 10:01:04 2026
(r1938456)
@@ -50,6 +50,189 @@
<toc/>
</section>
+ <section name="Fixed in Apache Tomcat 9.0.122" rtext="2026-09-15">
+
+ <p><strong>Low: WebSocket message smuggling with
+ per-message-deflate</strong>
+ <cve>CVE-2026-87022</cve></p>
+
+ <p>Improper handling of length parameter allows WebSocket message smuggling
+ when per-message-deflate is used.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="959a52a227cc35101b92dae35b722546167594d6"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 7 September 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.0.M1 to 9.0.121</p>
+
+ <p><strong>Important: Regression in fix for CVE-2026-41293 can trigger
+ request header mix-up</strong>
+ <cve>CVE-2026-86350</cve></p>
+
+ <p>Inconsistent interpretation of HTTP/2 requests caused by a regression in
+ fix for CVE-2026-41293 can trigger request header mix-up.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="5adadc4ef413d5050f664d40800bbff74bd5d5ed"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 28 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.118 to 9.0.121</p>
+
+ <p><strong>Moderate: Fix for CVE-2026-34500 was incomplete. OCSP checks
+ sometimes soft-fail with FFM even when soft-fail is disabled</strong>
+ <cve>CVE-2026-86248</cve></p>
+
+ <p>CLIENT_CERT authentication does not fail as expected for some scenarios
+ when OCSP soft fail is disabled.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="fc41d82e0e383e4d6e88ad321d245dafdc17d26d"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 28 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.92 to 9.0.121</p>
+
+ <p><strong>Moderate: WebSocket DoS due to lost asynchronous write
+ timeout</strong>
+ <cve>CVE-2026-79677</cve></p>
+
+ <p>Due to a concurrency bug, an attacker could trigger a denial of service
+ as a result of lost time outs for asynchronous WebSocket writes.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="c8fa5430233bca5b209c593dd446f88fda9d543e"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 25 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.0.M1 to 9.0.121</p>
+
+ <p><strong>Low: HTTP/2 DoS via malformed request</strong>
+ <cve>CVE-2026-78437</cve></p>
+
+ <p>A malformed HTTP/2 request could potentially (depends on timing) cause
+ one request from another user to fail.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="a28c35055ab11d35929ad564beb1a23a67b39546"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 24 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.116 to 9.0.121</p>
+
+ <p><strong>Important: AJP DoS via missing request body</strong>
+ <cve>CVE-2026-78383</cve></p>
+
+ <p>If the end user did not provide a request body, that could pin an AJP
+ processing thread leading to denial of service.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="265bdc0a58b1447ff5d8f8b96ea81de58cb74c8c"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 24 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.0.M1 to 9.0.121</p>
+
+ <p><strong>Important: DoS via busy wait during WebSocket close</strong>
+ <cve>CVE-2026-77791</cve></p>
+
+ <p>A busy wait during sending of WebSocket close message enabled a DoS
+ attack.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="7a5945f1de1d3310214234dfbbd7c569af52d058"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 21 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.74 to 9.0.121</p>
+
+ <p><strong>Low: Stale HPACK emitter injects trailers into recycled pooled
+ Request</strong>
+ <cve>CVE-2026-77762</cve></p>
+
+ <p>A race condition allowed an attacker to inject trailer fields into
+ another HTTP/2 request.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="71f27c2e84810930beda468b5ba732dcd0ef2652"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 21 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.39 to 9.0.121</p>
+
+ <p><strong>Low: Transfer-Encoding honored for HTTP/1.0 requests</strong>
+ <cve>CVE-2026-77756</cve></p>
+
+ <p>Processing the transfer-encoding header for an HTTP/1.0 request may
allow
+ an attacker to cause one request from another user to fail when Tomcat
is
+ located behind a reverse proxy.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="e590588ab7649c93d49b0eb7b3152700a977880d"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 20 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.47 to 9.0.121</p>
+
+ <p><strong>Important: Bypass of security constraints for WebSocket
+ endpoints</strong>
+ <cve>CVE-2026-76183</cve></p>
+
+ <p>Request paths were incorrectly parsed as endpoint templates allowing the
+ bypass of security constraints for WebSocket endpoints.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="a93a60a33f4cc202542eb6a0b87b7142d7db311c"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 17 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.0.M1 to 9.0.121</p>
+
+ <p><strong>Low: Cross-context authentication mix-up with Jakarta
+ Authentication configured</strong>
+ <cve>CVE-2026-75973</cve></p>
+
+ <p>When Jakarta Authentication was configured with SimpleAuthConfigProvider
+ as the default provider and multiple web application used that provider,
+ the realm for the first web application to authenticate a request would
+ be used for all web applications.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="043115414a39127cad015e9d285296e59c18bb41"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 13 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.0.M4 to 9.0.121</p>
+
+ <p><strong>Moderate: OpenSSL and OpenSSL-FFM TLS implementations ignore
CRLs
+ when certificate uses a keystore</strong>
+ <cve>CVE-2026-73581</cve></p>
+
+ <p>Both the OpenSSL and OpenSSL-FFM TLS implementations ignored CRLs when
+ certificate used a keystore.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="2dce8f26b3ba6a89c8f172b94fa41a5fa2dcc361"/>.</p>
+
+ <p>This issue was reported to the Tomcat security team on 11 August 2026.
+ The issue was made public on 23 September 2026.</p>
+
+ <p>Affects: 9.0.0.M1 to 9.0.121</p>
+
+ </section>
+
<section name="Fixed in Apache Tomcat 9.0.121" rtext="2026-08-18">
<p><strong>Low: Authenticated WebSocket session survives end of HTTP
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]