dev
Thread
Date
Earlier messages
Later messages
Messages by Thread
(tomcat) branch 11.0.x updated: Ensure non-blocking write buffer is empty before sending AJP end msg
markt
(tomcat) branch main updated: Ensure non-blocking write buffer is empty before sending AJP end msg
markt
(tomcat) branch 11.0.x updated: Add test case for CVE-2026-78437
markt
(tomcat) branch 10.1.x updated: Move to 27-ea
remm
[Bug 69949] Corrupted uploads from Safari on Tomcat 9/10/11
bugzilla
(tomcat) branch main updated: Improve handling of Servlet 5.7 response closure
markt
(tomcat) branch main updated (19a8077cd3 -> e5a5d87495)
markt
(tomcat) 03/03: Add test case for CVE-2026-78437
markt
(tomcat) 02/03: Add test case for CVE-2026-77791
markt
(tomcat) 01/03: Add test case for CVE-2026-77762
markt
(tomcat) branch 11.0.x updated: Improve handling of Servlet 5.7 response closure
markt
(tomcat) branch 9.0.x updated: Align flushing buffered writes with HTTP.
markt
(tomcat) branch 10.1.x updated: Align flushing buffered writes with HTTP.
markt
(tomcat) branch 11.0.x updated: Align flushing buffered writes with HTTP.
markt
(tomcat) branch main updated: Align flushing buffered writes with HTTP.
markt
(tomcat) branch main updated: Clean-up - no functional change
markt
(tomcat) branch 9.0.x updated: Clean-up - no functional change
markt
(tomcat) branch 10.1.x updated: Clean-up - no functional change
markt
(tomcat) branch 11.0.x updated: Clean-up - no functional change
markt
(tomcat) branch 9.0.x updated: Add test case for CVE-2026-78437
markt
(tomcat) branch 11.0.x updated: Add test case for CVE-2026-77791
markt
(tomcat) branch main updated: Avoid very rare race between async write notification and completion
remm
NSIS 3.13 released ...
Rainer Jung
Re: NSIS 3.13 released ...
Mark Thomas
(tomcat) branch 10.1.x updated: Add test case for CVE-2026-78437
markt
(tomcat) branch 9.0.x updated: Add test case for CVE-2026-77791
markt
(tomcat) branch 10.1.x updated: Add test case for CVE-2026-77791
markt
(tomcat) branch 9.0.x updated: Add test case for CVE-2026-77762
markt
(tomcat) branch 10.1.x updated: Add test case for CVE-2026-77762
markt
(tomcat) branch 11.0.x updated: Add test case for CVE-2026-77762
markt
(tomcat) branch main updated (a67bd12758 -> 19a8077cd3)
remm
(tomcat) 01/01: Merge pull request #1056 from apache/dependabot/github_actions/actions/setup-java-6
remm
(tomcat) branch dependabot/github_actions/actions/setup-java-6 deleted (was 52f6d081e0)
github-bot
(tomcat) branch 11.0.x updated: Move to 27-ea
remm
(tomcat) branch main updated: Drop 26
remm
[PR] Route JspC context logging through Ant [tomcat]
via GitHub
Re: [PR] Route JspC context logging through Ant [tomcat]
via GitHub
Re: [PR] Route JspC context logging through Ant [tomcat]
via GitHub
(tomcat-connectors) branch main updated: Better length checks when processing response header values.
markt
(tomcat-connectors) branch main updated: Add a lower bounds check for encoded response headers
markt
svn commit: r1938614 - in tomcat/site/trunk: docs xdocs
markt
(tomcat) branch 11.0.x updated: Add test case for bug 70249
markt
(tomcat) branch 9.0.x updated: Add test case for bug 70249
markt
(tomcat) branch 10.1.x updated: Add test case for bug 70249
markt
(tomcat) branch main updated: Add test case for bug 70249
markt
(tomcat) branch main updated: Fix a Coverity resource leak warning.
markt
(tomcat) branch 10.1.x updated: Typos
remm
(tomcat) branch 11.0.x updated: Typos
remm
(tomcat) branch 9.0.x updated: Typos
remm
(tomcat) branch main updated: Typos
remm
[PR] Bump jakarta.tck:sigtest-maven-plugin from 2.6 to 2.7 [tomcat-tck]
via GitHub
[PR] Bump org.apache.maven.plugins:maven-install-plugin from 3.1.4 to 3.2.0 [tomcat-tck]
via GitHub
(tomcat-tck) branch dependabot/maven/jakarta.tck-sigtest-maven-plugin-2.7 created (now c5b40e3)
github-bot
(tomcat-tck) branch dependabot/maven/org.junit-junit-bom-6.1.3 created (now 8028a24)
github-bot
(tomcat-tck) branch dependabot/maven/org.slf4j-slf4j-simple-2.0.20 created (now 0d19279)
github-bot
[PR] Bump org.slf4j:slf4j-simple from 2.0.18 to 2.0.20 [tomcat-tck]
via GitHub
[PR] Bump org.junit:junit-bom from 6.1.0 to 6.1.3 [tomcat-tck]
via GitHub
(tomcat-tck) branch dependabot/maven/org.apache.maven.plugins-maven-install-plugin-3.2.0 created (now 476df0b)
github-bot
(tomcat-jakartaee-migration) branch dependabot/maven/org.apache-apache-40 deleted (was f69bb56)
github-bot
(tomcat-jakartaee-migration) branch main updated: Bump org.apache:apache from 39 to 40
remm
[Bug 69890] Update test-status for more clear output
bugzilla
[Bug 69890] Update test-status for more clear output
bugzilla
(tomcat-jakartaee-migration) branch dependabot/maven/org.apache-apache-40 created (now f69bb56)
github-bot
[PR] Bump org.apache:apache from 39 to 40 [tomcat-jakartaee-migration]
via GitHub
Re: [PR] Bump org.apache:apache from 39 to 40 [tomcat-jakartaee-migration]
via GitHub
[Bug 70249] New: EL in Tomcat 12-M1: NPE coerceToNumber()
bugzilla
[Bug 70249] EL in Tomcat 12-M1: NPE coerceToNumber()
bugzilla
[Bug 70249] EL in Tomcat 12-M1: NPE coerceToNumber()
bugzilla
(tomcat) branch 9.0.x updated: Fix possible corruption with HTTP/2 and large uploads
remm
(tomcat) branch 10.1.x updated: Fix possible corruption with HTTP/2 and large uploads
remm
(tomcat) branch 11.0.x updated: Fix possible corruption with HTTP/2 and large uploads
remm
(tomcat) branch main updated: Fix possible corruption with HTTP/2 and large uploads
remm
[PR] Fix data corruption in SocketBufferHandler.unReadReadBuffer() [tomcat]
via GitHub
Re: [PR] Fix data corruption in SocketBufferHandler.unReadReadBuffer() [tomcat]
via GitHub
Re: [PR] Fix data corruption in SocketBufferHandler.unReadReadBuffer() [tomcat]
via GitHub
Re: [PR] Fix data corruption in SocketBufferHandler.unReadReadBuffer() [tomcat]
via GitHub
Re: [PR] Fix data corruption in SocketBufferHandler.unReadReadBuffer() [tomcat]
via GitHub
Re: [PR] Fix data corruption in SocketBufferHandler.unReadReadBuffer() [tomcat]
via GitHub
Re: [PR] Fix data corruption in SocketBufferHandler.unReadReadBuffer() [tomcat]
via GitHub
(tomcat) branch 10.1.x updated: Update the internal fork of Apache Commons BCEL to 6.13.0
markt
(tomcat) branch 9.0.x updated: Update the internal fork of Apache Commons BCEL to 6.13.0
markt
(tomcat) branch 11.0.x updated: Update the internal fork of Apache Commons BCEL to 6.13.0
markt
(tomcat) branch main updated: Update the internal fork of Apache Commons BCEL to 6.13.0
markt
(tomcat) branch main updated: Fix checkstyle error
markt
(tomcat) branch main updated: Another round of documentation updates for clusters with TLS
markt
(tomcat) branch main updated: Fixes for MembershipServiceBase with TLS-PSK
markt
(tomcat) branch main updated: Fix issue with some missing messages
markt
(tomcat) branch main updated: LibreSSL does not support PSK at all
remm
(tomcat) branch main updated: Hopefully the final check to fix to MacOS smoke test
markt
(tomcat) branch main updated: Better fix for test failures on Java 21 and earlier
markt
(tomcat) branch main updated: Fix LibreSSL compatibility
remm
Re: (tomcat) branch main updated: Fix LibreSSL compatibility
Rémy Maucherat
(tomcat) branch main updated: Add a note re LibreSSL
markt
(tomcat) branch main updated: Revert "Add OpenSSL support to the MacOS smoketest"
markt
(tomcat) branch main updated: Move SSL_in_init to compat
remm
Re: (tomcat) branch main updated: Move SSL_in_init to compat
Rémy Maucherat
(tomcat) branch main updated: Add OpenSSL support to the MacOS smoketest
markt
Re: (tomcat) branch main updated: Add OpenSSL support to the MacOS smoketest
Rémy Maucherat
Re: (tomcat) branch main updated: Add OpenSSL support to the MacOS smoketest
Mark Thomas
(tomcat) branch main updated: Skip FFM tests if running on Java 21 or earlier
markt
Re: (tomcat) branch main updated: Skip FFM tests if running on Java 21 or earlier
Mark Thomas
[PR] Bring back OpenSSL 1.1.1 support [tomcat-native]
via GitHub
Re: [PR] Bring back OpenSSL 1.1.1 support [tomcat-native]
via GitHub
Re: [PR] Bring back OpenSSL 1.1.1 support [tomcat-native]
via GitHub
(tomcat) branch main updated: Expands tests
markt
(tomcat) branch main updated (2db121ddce -> 1de7fac738)
markt
(tomcat) 01/02: Align with Tomcat Native 1.2.x
markt
(tomcat) 02/02: First pass at TLS 1.3 support
markt
(tomcat-native) branch main updated: Further fix for TLS 1.3 PSK support
markt
(tomcat) branch main updated: And some more deprecation
markt
(tomcat) branch main updated: Additional deprecation
markt
(tomcat-native) branch main updated: Complete the PSK support with client-side TLS 1.3
markt
[Bug 70248] New: Uploads fail over HTTP/2: Tomcat closes the connection with "payload is [16777215] bytes long but the maximum frame size is [16384]"
bugzilla
[Bug 70248] Uploads fail over HTTP/2: Tomcat closes the connection with "payload is [16777215] bytes long but the maximum frame size is [16384]"
bugzilla
TLS support for tribes (clustering)
Mark Thomas
Re: TLS support for tribes (clustering)
Mark Thomas
(tomcat) branch main updated (85d7b3a067 -> bb4e829af0)
markt
(tomcat) 03/03: Update docs to recommend TLS rather than EncryptInterceptor
markt
(tomcat) 01/03: Align naming
markt
(tomcat) 02/03: Complete securePort support for DNS membership (untested)
markt
(tomcat) branch main updated (a0c3ab5657 -> 85d7b3a067)
markt
(tomcat) 01/02: Better logging for secure vs non-secure cluster configuration
markt
(tomcat) 02/02: Fix various edge cases for secure only configurations
markt
(tomcat-maven-plugin) branch dependabot/maven/org.apache-apache-40 deleted (was f11a94b)
github-bot
(tomcat-maven-plugin) branch trunk updated (9799978 -> e6b55d1)
remm
(tomcat-maven-plugin) 01/01: Merge pull request #139 from apache/dependabot/maven/org.apache-apache-40
remm
(tomcat-tck) branch dependabot/maven/org.apache.maven.plugins-maven-failsafe-plugin-3.5.6 deleted (was 9e5c162)
github-bot
(tomcat-tck) branch main updated: Bump org.apache.maven.plugins:maven-failsafe-plugin from 3.5.5 to 3.6.0
markt
Re: [PR] Bump org.apache.maven.plugins:maven-failsafe-plugin from 3.5.5 to 3.6.0 [tomcat-tck]
via GitHub
(tomcat-tck) branch dependabot/maven/org.apache.maven.plugins-maven-failsafe-plugin-3.5.6 updated (d57b77a -> 9e5c162)
github-bot
Re: [PR] Bump org.apache.maven.plugins:maven-failsafe-plugin from 3.5.5 to 3.5.6 [tomcat-tck]
via GitHub
Re: [PR] Bump org.apache.maven.plugins:maven-failsafe-plugin from 3.5.5 to 3.5.6 [tomcat-tck]
via GitHub
Re: [PR] Bump org.apache.maven.plugins:maven-failsafe-plugin from 3.5.5 to 3.5.6 [tomcat-tck]
via GitHub
(tomcat-tck) branch dependabot/maven/org.jboss.arquillian.container-arquillian-tomcat-embedded-10-1.2.5.Final deleted (was a16b248)
github-bot
(tomcat-tck) branch main updated: Bump org.jboss.arquillian.container:arquillian-tomcat-embedded-10
markt
(tomcat-tck) branch dependabot/maven/org.jboss.arquillian.container-arquillian-tomcat-embedded-10-1.2.5.Final updated (891ce31 -> a16b248)
github-bot
Re: [PR] Bump org.jboss.arquillian.container:arquillian-tomcat-embedded-10 from 1.2.4.Final to 1.2.5.Final [tomcat-tck]
via GitHub
Re: [PR] Bump org.jboss.arquillian.container:arquillian-tomcat-embedded-10 from 1.2.4.Final to 1.2.5.Final [tomcat-tck]
via GitHub
(tomcat-tck) branch dependabot/maven/org.apache.maven.plugins-maven-failsafe-plugin-3.5.6 updated (9633c66 -> d57b77a)
markt
Re: [PR] Bump org.jacoco:jacoco-maven-plugin from 0.8.14 to 0.8.15 [tomcat-tck]
via GitHub
(tomcat-tck) branch dependabot/maven/org.jacoco-jacoco-maven-plugin-0.8.15 deleted (was c244d94)
github-bot
(tomcat-tck) branch main updated: Bump org.jacoco:jacoco-maven-plugin from 0.8.14 to 0.8.15
markt
(tomcat-tck) branch main updated: Bump org.junit:junit-bom from 6.0.3 to 6.1.0
markt
Re: [PR] Bump org.junit:junit-bom from 6.0.3 to 6.1.0 [tomcat-tck]
via GitHub
(tomcat-tck) branch dependabot/maven/org.junit-junit-bom-6.1.0 deleted (was 6712131)
github-bot
Re: [PR] Bump arquillian.version from 1.10.1.Final to 1.10.2.Final [tomcat-tck]
via GitHub
(tomcat-tck) branch dependabot/maven/arquillian.version-1.10.2.Final deleted (was 0752955)
github-bot
(tomcat-tck) branch main updated: Bump arquillian.version from 1.10.1.Final to 1.10.2.Final
markt
[SECURITY] CVE-2026-79677 Apache Tomcat - WebSocket DoS due to lost asynchronous write timeout
Mark Thomas
[UPDATE][SECURITY] CVE-2026-79677 Apache Tomcat - WebSocket DoS due to lost asynchronous write timeout
Mark Thomas via dev
[UPDATE][SECURITY] CVE-2026-79677 Apache Tomcat - WebSocket DoS due to lost asynchronous write timeout
Mark Thomas
(tomcat-native) branch 1.3.x updated: Stop OCSP checks once a cert in the trust store is reached
markt
(tomcat-native) branch main updated: Stop OCSP checks once a cert in the trust store is reached
markt
[SECURITY] CVE-2026-86247 Apache Tomcat Native - Client certificate requirements can be down-graded
Mark Thomas
[SECURITY] CVE-2026-86246 Apache Tomcat Native - Insecure OpenSSL options enabled
Mark Thomas
[SECURITY] CVE-2026-86243 Apache Tomcat Native - DoS via TLS handshake
Mark Thomas
svn commit: r1938458 - in tomcat/site/trunk: docs xdocs
markt
[SECURITY] CVE-2026-77791 Apache Tomcat - DoS via busy wait during WebSocket close
Mark Thomas
[UPDATE][SECURITY] CVE-2026-77791 Apache Tomcat - DoS via busy wait during WebSocket close
Mark Thomas via dev
[UPDATE][SECURITY] CVE-2026-77791 Apache Tomcat - DoS via busy wait during WebSocket close
Mark Thomas
[SECURITY] CVE-2026-78437 Apache Tomcat - HTTP/2 DoS via malformed request
Mark Thomas
[UPDATE][SECURITY] CVE-2026-78437 Apache Tomcat - HTTP/2 DoS via malformed request
Mark Thomas
[UPDATE][SECURITY] CVE-2026-78437 Apache Tomcat - HTTP/2 DoS via malformed request
Mark Thomas via dev
[SECURITY] CVE-2026-87022 Apache Tomcat - WebSocket message smuggling with per-message-deflate
Mark Thomas
[UPDATE][SECURITY] CVE-2026-87022 Apache Tomcat - WebSocket message smuggling with per-message-deflate
Mark Thomas via dev
[UPDATE][SECURITY] CVE-2026-87022 Apache Tomcat - WebSocket message smuggling with per-message-deflate
Mark Thomas
[SECURITY] CVE-2026-86350 Apache Tomcat - Regression in fix for CVE-2026-41293 can trigger request header mix-up
Mark Thomas
[UPDATE][SECURITY] CVE-2026-86350 Apache Tomcat - Regression in fix for CVE-2026-41293 can trigger request header mix-up
Mark Thomas via dev
[UPDATE][SECURITY] CVE-2026-86350 Apache Tomcat - Regression in fix for CVE-2026-41293 can trigger request header mix-up
Mark Thomas
[SECURITY] CVE-2026-86248 Apache Tomcat - Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas
[UPDATE][SECURITY] CVE-2026-86248 Apache Tomcat - Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas via dev
[UPDATE][SECURITY] CVE-2026-86248 Apache Tomcat - Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas
[SECURITY] CVE-2026-78383 Apache Tomcat - AJP DoS via missing request body
Mark Thomas
[UPDATE][SECURITY] CVE-2026-78383 Apache Tomcat - AJP DoS via missing request body
Mark Thomas
[UPDATE][SECURITY] CVE-2026-78383 Apache Tomcat - AJP DoS via missing request body
Mark Thomas via dev
[SECURITY] CVE-2026-77762 Apache Tomcat - Stale HPACK emitter injects trailers into recycled pooled Request
Mark Thomas
[UPDATE][SECURITY] CVE-2026-77762 Apache Tomcat - Stale HPACK emitter injects trailers into recycled pooled Request
Mark Thomas via dev
[UPDATE][SECURITY] CVE-2026-77762 Apache Tomcat - Stale HPACK emitter injects trailers into recycled pooled Request
Mark Thomas
[SECURITY] CVE-2026-77756 Apache Tomcat - Transfer-Encoding honored for HTTP/1.0 requests
Mark Thomas
[UPDATE][SECURITY] CVE-2026-77756 Apache Tomcat - Transfer-Encoding honored for HTTP/1.0 requests
Mark Thomas via dev
[UPDATE][SECURITY] CVE-2026-77756 Apache Tomcat - Transfer-Encoding honored for HTTP/1.0 requests
Mark Thomas
[SECURITY] CVE-2026-76183 Apache Tomcat - Bypass of security constraints for WebSocket endpoints
Mark Thomas
[UPDATE][SECURITY] CVE-2026-76183 Apache Tomcat - Bypass of security constraints for WebSocket endpoints
Mark Thomas via dev
[UPDATE][SECURITY] CVE-2026-76183 Apache Tomcat - Bypass of security constraints for WebSocket endpoints
Mark Thomas
[SECURITY] CVE-2026-75973 Apache Tomcat - Cross-context authentication mix-up with Jakarta Authentication configured
Mark Thomas
[UPDATE][SECURITY] CVE-2026-75973 Apache Tomcat - Cross-context authentication mix-up with Jakarta Authentication configured
Mark Thomas
[UPDATE][SECURITY] CVE-2026-75973 Apache Tomcat - Cross-context authentication mix-up with Jakarta Authentication configured
Mark Thomas via dev
[SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
Mark Thomas
[UPDATE][SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
Mark Thomas
svn commit: r1938456 - in tomcat/site/trunk: docs xdocs
markt
(tomcat) branch main updated: Suppress IDE warning
markt
(tomcat) branch main updated (590267e7ef -> 23f25ee5c3)
markt
(tomcat) 01/02: Implement TSL-PSK encryption for clustering
markt
Re: (tomcat) 01/02: Implement TSL-PSK encryption for clustering
Mark Thomas
Re: (tomcat) 01/02: Implement TSL-PSK encryption for clustering
Rémy Maucherat
(tomcat) 02/02: Clarify the exclusion
markt
(tomcat-maven-plugin) branch dependabot/maven/org.apache-apache-40 created (now f11a94b)
github-bot
(tomcat-maven-plugin) branch dependabot/maven/org.apache-apache-39 deleted (was ffa6f99)
github-bot
[PR] Bump org.apache:apache from 38 to 40 [tomcat-maven-plugin]
via GitHub
Re: [PR] Bump org.apache:apache from 38 to 40 [tomcat-maven-plugin]
via GitHub
Earlier messages
Later messages