This bug was fixed in the package tomcat10 - 10.1.57~us1-0ubuntu1
---------------
tomcat10 (10.1.57~us1-0ubuntu1) stonking; urgency=medium
* New upstream release 10.1.57 (LP: #2161376).
- CVEs (10.1.57):
+ CVE-2026-59084: Low: EncryptInterceptor requirements not
clearly documented
+ CVE-2026-59083: Low: Incorrect URL decoding in RewriteValve
may allow security control bypass
- CVEs (10.1.56):
+ CVE-2026-55956: Moderate: Security constraints for default
servlet ignored method
+ CVE-2026-55955: Low: EncryptInterceptor not protected against
replay attacks
+ CVE-2026-55276: Low: Logged effective web.xml is incomplete
+ CVE-2026-53434: Low: Invalid CRL configuration doesn't trigger
failure for FFM Connector
+ CVE-2026-53404: Low: Bad ornext processing in RewriteValve
+ CVE-2026-50229: Low: XSS in number guess example
* d/t/control: add rw-build-tree restriction for junit test.
* d/t/control: run unit test only for arm64 and amd64. Tests will
time out on zero JVM architectures.
* d/t/smoke: use retry and wait up to 180 seconds before the test
fail.
-- Vladimir Petko <[email protected]> Mon, 20 Jul 2026
10:54:32 +1200
** Changed in: tomcat10 (Ubuntu Stonking)
Status: New => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-50229
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53404
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53434
** CVE added: https://cve.org/CVERecord?id=CVE-2026-55276
** CVE added: https://cve.org/CVERecord?id=CVE-2026-55955
** CVE added: https://cve.org/CVERecord?id=CVE-2026-55956
** CVE added: https://cve.org/CVERecord?id=CVE-2026-59083
** CVE added: https://cve.org/CVERecord?id=CVE-2026-59084
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2161376
Title:
Tomcat 10, 11 July updates
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/tomcat-native/+bug/2161376/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs