Hi,
The following vulnerabilities were published for tomcat11.
CVE-2026-73581[0]:
| Improper Check for Certificate Revocation vulnerability in Apache
| Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore
| CRLs when certificate uses a keystore. This issue affects Apache
| Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through
| 10.1.58, from 9.0.0-M1 through 9.0.121. The following versions
| were EOL at the time the CVE was created but are known to be
| affected: from 8.5.0 through 8.5.100. Other unsupported versions may
| also be affected. Users are recommended to upgrade to version
| 11.0.26, 10.1.59, 9.0.122, which fixes the issue.
CVE-2026-75973[1]:
| Improper Authentication vulnerability in Apache Tomcat. When Jakarta
| Authentication was configured with SimpleAuthConfigProvider as the
| default provider and multiple web application used that provider,
| the realm for the first web application to authenticate a request
| would be used for all web applications. This issue affects Apache
| Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through
| 10.1.59, from 9.0.0.M4 through 9.0.121. The following versions
| were EOL at the time the CVE was created but are known to be
| affected: from 8.5.0 through 8.5.100. Other unsupported versions may
| also be affected. Users are recommended to upgrade to version
| 11.0.26, 10.1.60, 9.0.122, which fixes the issue.
CVE-2026-76183[2]:
| Authentication Bypass by Alternate Name vulnerability in Apache
| Tomcat allowed the security constraints for any WebSocket endpoint
| to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1
| through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1
| through 9.0.121. The following versions were EOS at the time the
| CVE was created but are known to be affected: from 8.5.0 through
| 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may
| also be affected. Users are recommended to upgrade to version
| 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
CVE-2026-77756[3]:
| Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response
| Smuggling') vulnerability in Apache Tomcat caused by processing the
| transfer-encoding header for an HTTP/1.0 request may allow an
| attacker to cause one request from another user to fail when Tomcat
| is located behind a reverse proxy. This issue affects Apache
| Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through
| 10.1.59, from 9.0.47 through 9.0.121. The following versions were
| EOL at the time the CVE was created but are known to be affected:
| from 8.5.67 through 8.5.100. Other unsupported versions may also be
| affected. Users are recommended to upgrade to version 11.0.26,
| 10.1.60 or 9.0.122, which fix the issue.
CVE-2026-77762[4]:
| Concurrent Execution using Shared Resource with Improper
| Synchronization ('Race Condition') vulnerability in Apache Tomcat
| allows an attacker to inject trailer fields into another HTTP/2
| request. This issue affects Apache Tomcat: from 11.0.0-M1 through
| 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.39 through
| 9.0.121. The following versions were EOL at the time the CVE was
| created but are known to be affected: from 8.5.59 through 8.5.100.
| Other unsupported versions may also be affected. Users are
| recommended to upgrade to version 11.0.26, 10.1.60, 9.0.122, which
| fix the issue.
CVE-2026-77791[5]:
| Uncontrolled Resource Consumption vulnerability in Apache Tomcat
| during sending of WebSocket close message enabled a DoS attack.
| This issue affects Apache Tomcat: from 11.0.0-M5 through 11.0.25,
| from 10.1.8 through 10.1.59, from 9.0.74 through 9.0.121. The
| following versions were EOL at the time the CVE was created but are
| known to be affected: from 8.5.88 through 8.5.100. Other unsupported
| versions may also be affected. Users are recommended to upgrade
| to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
CVE-2026-78383[6]:
| Allocation of resources without limits or throttling vulnerability
| in Apache Tomcat allows an unauthenticated AJP request to pin an AJP
| processing thread leading to denial of service. This issue
| affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from
| 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The
| following versions were EOL at the time the CVE was created but are
| known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through
| 7.0.109. Other unsupported versions may also be affected. Users
| are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122,
| which fix the issue.
CVE-2026-78437[7]:
| Incomplete cleanup vulnerability in Apache Tomcat allows a malformed
| request to potentially (depends on timing) cause one request from
| another user to fail. This issue affects Apache Tomcat: from
| 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116
| through 9.0.121. Users are recommended to upgrade to version
| 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
CVE-2026-79677[8]:
| Missing release of resource after effective lifetime, Comparison
| using wrong factors vulnerability in Apache Tomcat allows a denial
| of service as a result of lost time outs for asynchronous WebSocket
| writes. This issue affects Apache Tomcat: from 11.0.0-M1 through
| 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through
| 9.0.121. The following versions were EOL at the time the CVE was
| created but are known to be affected: from 8.5.0 through 8.5.100,
| from 7.0.43 through 7.0.109. Other unsupported versions may also be
| affected. Users are recommended to upgrade to version 11.0.26,
| 10.1.60 or 9.0.122, which fix the issue.
CVE-2026-86248[9]:
| CLIENT_CERT authentication does not fail as expected for some
| scenarios when soft fail is disabled vulnerability in Apache Tomcat.
| This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25,
| from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121. Users
| are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122,
| which fix the issue.
CVE-2026-86350[10]:
| Inconsistent interpretation of HTTP/2 requests ('HTTP
| Request/Response smuggling') vulnerability in Apache Tomcat caused
| by a regression in fix for CVE-2026-41293 can trigger request header
| mix-up. This issue affects Apache Tomcat: from 11.0.22 through
| 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121.
| Users are recommended to upgrade to version 11.0.26, 10.1.60 or
| 9.0.122, which fix the issue.
CVE-2026-87022[11]:
| Improper handling of length parameter inconsistency vulnerability in
| Apache Tomcat allows WebSocket message smuggling when per-message-
| deflate is used. This issue affects Apache Tomcat: from 11.0.0-M1
| through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1
| through 9.0.121. The following versions were EOS at the time the
| CVE was created but are known to be affected: from 8.5.0 through
| 8.5.100, from 7.0.56 through 7.0.109. Other unsupported versions may
| also be affected. Users are recommended to upgrade to version
| 11.0.26, 10.1.60 or 9.1.22, which fix the issue.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-73581
https://www.cve.org/CVERecord?id=CVE-2026-73581
[1] https://security-tracker.debian.org/tracker/CVE-2026-75973
https://www.cve.org/CVERecord?id=CVE-2026-75973
[2] https://security-tracker.debian.org/tracker/CVE-2026-76183
https://www.cve.org/CVERecord?id=CVE-2026-76183
[3] https://security-tracker.debian.org/tracker/CVE-2026-77756
https://www.cve.org/CVERecord?id=CVE-2026-77756
[4] https://security-tracker.debian.org/tracker/CVE-2026-77762
https://www.cve.org/CVERecord?id=CVE-2026-77762
[5] https://security-tracker.debian.org/tracker/CVE-2026-77791
https://www.cve.org/CVERecord?id=CVE-2026-77791
[6] https://security-tracker.debian.org/tracker/CVE-2026-78383
https://www.cve.org/CVERecord?id=CVE-2026-78383
[7] https://security-tracker.debian.org/tracker/CVE-2026-78437
https://www.cve.org/CVERecord?id=CVE-2026-78437
[8] https://security-tracker.debian.org/tracker/CVE-2026-79677
https://www.cve.org/CVERecord?id=CVE-2026-79677
[9] https://security-tracker.debian.org/tracker/CVE-2026-86248
https://www.cve.org/CVERecord?id=CVE-2026-86248
[10] https://security-tracker.debian.org/tracker/CVE-2026-86350
https://www.cve.org/CVERecord?id=CVE-2026-86350
[11] https://security-tracker.debian.org/tracker/CVE-2026-87022
https://www.cve.org/CVERecord?id=CVE-2026-87022
Regards,
Salvatore