#1142454 tomcat11: CVE-2026-59083 CVE-2026-59084

Package:
src:tomcat11
Source:
src:tomcat11
Submitter:
Salvatore Bonaccorso
Date:
2026-07-20 08:09:02 UTC
Severity:
normal
Tags:
#1142454#5
Date:
2026-07-20 08:07:50 UTC
From:
To:
Hi,

The following vulnerabilities were published for tomcat11.

CVE-2026-59083[0]:
| Improper Handling of URL Encoding (Hex Encoding) vulnerability in
| Apache Tomcat's rewrite valve allowed security constraint bypass for
| some configurations.  This issue affects Apache Tomcat: from
| 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from
| 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions
| that have reached end of support may also be affected.  Users are
| recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which
| fix the issue.


CVE-2026-59084[1]:
| Insufficient Technical Documentation vulnerability in Apache Tomcat
| since the requirements to securely configure the EncryptInterceptor
| were not clearly documented.  This issue affects Apache Tomcat: from
| 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from
| 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100
| through 7.0.109. Other versions that have reached end of support may
| also be affected.  Users are recommended to upgrade to version
| 11.0.24, 10.1.57 or 9.0.120 which fix the issue.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-59083
https://www.cve.org/CVERecord?id=CVE-2026-59083
[1] https://security-tracker.debian.org/tracker/CVE-2026-59084
https://www.cve.org/CVERecord?id=CVE-2026-59084

Regards,
Salvatore