svn commit: r1937457 - in tomcat/site/trunk: docs xdocs

[email protected]
Newsgroups gmane.comp.jakarta.tomcat.devel
Message-ID <178769353615.2260121.11506085606258010209@svn03-he-fi>
Author: markt
Date: Tue Aug 25 21:32:15 2026
New Revision: 1937457

Log:
Publish CVE info for August releases

Modified:
   tomcat/site/trunk/docs/security-10.html
   tomcat/site/trunk/docs/security-11.html
   tomcat/site/trunk/docs/security-9.html
   tomcat/site/trunk/xdocs/security-10.xml
   tomcat/site/trunk/xdocs/security-11.xml
   tomcat/site/trunk/xdocs/security-9.xml

Modified: tomcat/site/trunk/docs/security-10.html
==============================================================================
--- tomcat/site/trunk/docs/security-10.html	Tue Aug 25 21:16:50 2026	(r1937456)
+++ tomcat/site/trunk/docs/security-10.html	Tue Aug 25 21:32:15 2026	(r1937457)
@@ -51,6 +51,85 @@
        fix for these issues, version 10.1.58 is not included in the list of 
        affected versions.</i></p>
 
+    <p><strong>Low: Authenticated WebSocket session survives end of HTTP
+       session</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73180" rel="nofollow">CVE-2026-73180</a></p>
+
+    <p>If the session ID for an authenticated HTTP session was changed after a
+       WebSocket connection had been established under that authenticated HTTP
+       session, the WebSokcet session would not be closed as required by the
+       Jakarta WebSocket specification when the HTTP session ended.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/83427cbdb92ca41244dc3d242ca4308ed8ade7d3">83427cbd</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 30 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Important: DoS via allocation leak in HTTP/2 backlog tracking
+       when a stream is reset</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-68763" rel="nofollow">CVE-2026-68763</a></p>
+
+    <p>An allocation leak in the HTTP/2 backlog tracking when a stream was reset
+       could be manipulated to trigger a denial of service.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/19d40615620fe145e88536e2bd63c5f01077c253">19d40615</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 16 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Important: Principal lookup could fail open in some
+       cases</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-68569" rel="nofollow">CVE-2026-68569</a></p>
+
+    <p>For some authentication methods (e.g. CLIENT-CERT, SPNEGO), a user would
+       be authenticated even if the user did not exist in the
+       DataSourceRealm.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/3ff06ceb984edc2a3c9e0161b01e833c5e50ed4f">3ff06ceb</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 16 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Low: Redirect after FORM authentication may bypass method
+       specific constraints</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-68525" rel="nofollow">CVE-2026-68525</a></p>
+
+    <p>The FORM authentication process allowed the bypassing of a security
+       constraint that limited user access to a resource POST but not GET.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/58123aa468a20e2a079b7e0c68a4009e2475c098">58123aa4</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 15 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Low: Servlet role references can bypass declarative role
+       constraints</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66422" rel="nofollow">CVE-2026-66422</a></p>
+
+    <p><code>security-role-ref</code> definitions were incorrectly used as role
+       aliases within the Realm in additional to the correct usage with
+       <code>Request.isUserInRole()</code>.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/49506f6d5ad7cdef211ce1a4026a29183b3df5c7">49506f6d</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
     <p><strong>Low: DoS in WebSocket chat example</strong>
        <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66299" rel="nofollow">CVE-2026-66299</a></p>
 
@@ -69,6 +148,84 @@
        Users who followed the security guidance to remove the examples web
        application are not affected.</p>
 
+    <p><strong>Important: RewriteValve [N] restarts at the second rule and may
+       bypass access control</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65927" rel="nofollow">CVE-2026-65927</a></p>
+
+    <p>An off-by-one error impacting the [N] flag on the rewrite valves caused
+       rewrite processing to restart at the second rule rather than the first
+       rule.</p>
+
+    <p>This was fixed with commits
+       <a href="https://github.com/apache/tomcat/commit/3097902177a041a93476a036b9c8419b25d5cc0d">30979021</a> and
+       <a href="https://github.com/apache/tomcat/commit/7d2ae3952a39db5790dcfd36e5d79c75570a20ee">7d2ae395</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Low: Limited replay attack possible with DIGEST
+       authentication</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65905" rel="nofollow">CVE-2026-65905</a></p>
+
+    <p>If, before windowSize requests had been made, a client made a DIGEST
+       authenticated request with a nonceCount on the upper boundary of the
+       replay window then that request was replayable once only while the
+       associated nonceCount remained within the replay window.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/1c1a583ba57092206f77c375f45da12c99fb141d">1c1a583b</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Moderate: HTTP/2 no-authority bypass of strict SNI
+       validation</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65637" rel="nofollow">CVE-2026-65637</a></p>
+
+    <p>The fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32990" rel="nofollow">CVE-2026-32990</a> was incomplete.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/40012414df828a56126f76a7339669c7c919aae7">40012414</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.53 to 10.1.57</p>
+
+    <p><strong>Low: TOCTOU when setting specific permissions for Unix Domain
+       Sockets</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65183" rel="nofollow">CVE-2026-65183</a></p>
+
+    <p>A race condition when creating a Unix Domain Socket allowed an
+       unauthorised local user to access the Unix Domain Socket.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/d8bcec9a30788fd887f33890b77ae1b8cd5f1f7e">d8bcec9a</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 3 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Important: Security constraint bypass</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65182" rel="nofollow">CVE-2026-65182</a></p>
+
+    <p>The security constraint processing enabled a security constraint bypass
+       if a constraint for a longer path was specified before a more restrictive
+       constraint for a shorter sub-path.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/b79752d2a8578d94743e2a95c50af297f780c0df">b79752d2</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
   </div><h3 id="Fixed_in_Apache_Tomcat_10.1.57"><span class="pull-right">2026-07-07</span> Fixed in Apache Tomcat 10.1.57</h3><div class="text">
 
     <p><strong>Low: EncryptInterceptor requirements not clearly

Modified: tomcat/site/trunk/docs/security-11.html
==============================================================================
--- tomcat/site/trunk/docs/security-11.html	Tue Aug 25 21:16:50 2026	(r1937456)
+++ tomcat/site/trunk/docs/security-11.html	Tue Aug 25 21:32:15 2026	(r1937457)
@@ -39,6 +39,85 @@
     <ul><li><a href="#Fixed_in_Apache_Tomcat_11.0.25">Fixed in Apache Tomcat 11.0.25</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.24">Fixed in Apache Tomcat 11.0.24</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.23">Fixed in Apache Tomcat 11.0.23</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.22">Fixed in Apache Tomcat 11.0.22</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.21">Fixed in Apache Tomcat 11.0.21</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.20">Fixed in Apache Tomcat 11.0.20</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.18">Fixed in Apache Tomcat 11.0.18</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.15">Fixed in Apache Tomcat 11.0.15</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.12">Fixed in Apache Tomcat 11.0.12</a></li><li><a href="#Fixed_in_Apa
 che_Tomcat_11.0.11">Fixed in Apache Tomcat 11.0.11</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.10">Fixed in Apache Tomcat 11.0.10</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.9">Fixed in 
 Apache Tomcat 11.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.8">Fixed in Apache Tomcat 11.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.7">Fixed in Apache Tomcat 11.0.7</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.6">Fixed in Apache Tomcat 11.0.6</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.5">Fixed in Apache Tomcat 11.0.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.3">Fixed in Apache Tomcat 11.0.3</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.2">Fixed in Apache Tomcat 11.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.1">Fixed in Apache Tomcat 11.0.1</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.0">Fixed in Apache Tomcat 11.0.0</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.0-M21">Fixed in Apache Tomcat 11.0.0-M21</a></li><li><a href="#F
 ixed_in_Apache_Tomcat_11.0.0-M17">Fixed in Apache Tomcat 11.0.0-M17</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.0-M12">Fixed in Apache Tomcat 11.0.0-M12</a></li><li><a href="#Fixed_in_Apache_T
 omcat_11.0.0-M11">Fixed in Apache Tomcat 11.0.0-M11</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.0-M6">Fixed in Apache Tomcat 11.0.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.0-M5">Fixed in Apache Tomcat 11.0.0-M5</a></li><li><a href="#Fixed_in_Apache_Tomcat_11.0.0-M3">Fixed in Apache Tomcat 11.0.0-M3</a></li></ul>
   </div><h3 id="Fixed_in_Apache_Tomcat_11.0.25"><span class="pull-right">2026-08-18</span> Fixed in Apache Tomcat 11.0.25</h3><div class="text">
 
+    <p><strong>Low: Authenticated WebSocket session survives end of HTTP
+       session</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73180" rel="nofollow">CVE-2026-73180</a></p>
+
+    <p>If the session ID for an authenticated HTTP session was changed after a
+       WebSocket connection had been established under that authenticated HTTP
+       session, the WebSokcet session would not be closed as required by the
+       Jakarta WebSocket specification when the HTTP session ended.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/e617a5d483b78851d289ca8dc1d68c49b541b419">e617a5d4</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 30 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Important: DoS via allocation leak in HTTP/2 backlog tracking
+       when a stream is reset</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-68763" rel="nofollow">CVE-2026-68763</a></p>
+
+    <p>An allocation leak in the HTTP/2 backlog tracking when a stream was reset
+       could be manipulated to trigger a denial of service.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/2a5ec806971627943db18601203129d9c58d959f">2a5ec806</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 16 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Important: Principal lookup could fail open in some
+       cases</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-68569" rel="nofollow">CVE-2026-68569</a></p>
+
+    <p>For some authentication methods (e.g. CLIENT-CERT, SPNEGO), a user would
+       be authenticated even if the user did not exist in the
+       DataSourceRealm.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/790d6e2c3b4cd201a1fa556a23d5b7504dee18ad">790d6e2c</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 16 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Low: Redirect after FORM authentication may bypass method
+       specific constraints</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-68525" rel="nofollow">CVE-2026-68525</a></p>
+
+    <p>The FORM authentication process allowed the bypassing of a security
+       constraint that limited user access to a resource POST but not GET.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/10d048e16034ddf12055e0cede0da05b15c823b8">10d048e1</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 15 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Low: Servlet role references can bypass declarative role
+       constraints</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66422" rel="nofollow">CVE-2026-66422</a></p>
+
+    <p><code>security-role-ref</code> definitions were incorrectly used as role
+       aliases within the Realm in additional to the correct usage with
+       <code>Request.isUserInRole()</code>.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/2c2c510ab10ae7796de6c6f7b70abae85c99d30d">2c2c510a</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
     <p><strong>Low: DoS in WebSocket chat example</strong>
        <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66299" rel="nofollow">CVE-2026-66299</a></p>
 
@@ -57,6 +136,84 @@
        Users who followed the security guidance to remove the examples web
        application are not affected.</p>
 
+    <p><strong>Important: RewriteValve [N] restarts at the second rule and may
+       bypass access control</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65927" rel="nofollow">CVE-2026-65927</a></p>
+
+    <p>An off-by-one error impacting the [N] flag on the rewrite valves caused
+       rewrite processing to restart at the second rule rather than the first
+       rule.</p>
+
+    <p>This was fixed with commits
+       <a href="https://github.com/apache/tomcat/commit/bce83410ffb1542752d52b536257e81a5c8dfcb8">bce83410</a> and
+       <a href="https://github.com/apache/tomcat/commit/b80929d65be774dc90e378acdda2d16949d1e5f3">b80929d6</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Low: Limited replay attack possible with DIGEST
+       authentication</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65905" rel="nofollow">CVE-2026-65905</a></p>
+
+    <p>If, before windowSize requests had been made, a client made a DIGEST
+       authenticated request with a nonceCount on the upper boundary of the
+       replay window then that request was replayable once only while the
+       associated nonceCount remained within the replay window.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/c5f94ad1726e8399b77eb3fd69c811c1103894d6">c5f94ad1</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Moderate: HTTP/2 no-authority bypass of strict SNI
+       validation</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65637" rel="nofollow">CVE-2026-65637</a></p>
+
+    <p>The fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32990" rel="nofollow">CVE-2026-32990</a> was incomplete.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/8639b20f045c88f356b887204f52e897399f0de7">8639b20f</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.20 to 11.0.24</p>
+
+    <p><strong>Low: TOCTOU when setting specific permissions for Unix Domain
+       Sockets</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65183" rel="nofollow">CVE-2026-65183</a></p>
+
+    <p>A race condition when creating a Unix Domain Socket allowed an
+       unauthorised local user to access the Unix Domain Socket.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/4fb4523d70258614a00e7501ae0fdf3cdcbc2470">4fb4523d</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 3 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Important: Security constraint bypass</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65182" rel="nofollow">CVE-2026-65182</a></p>
+
+    <p>The security constraint processing enabled a security constraint bypass
+       if a constraint for a longer path was specified before a more restrictive
+       constraint for a shorter sub-path.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/8bafd79a3b54684e80e9cb1bafd4746aede7d3f5">8bafd79a</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
   </div><h3 id="Fixed_in_Apache_Tomcat_11.0.24"><span class="pull-right">2026-07-08</span> Fixed in Apache Tomcat 11.0.24</h3><div class="text">
 
     <p><strong>Low: EncryptInterceptor requirements not clearly

Modified: tomcat/site/trunk/docs/security-9.html
==============================================================================
--- tomcat/site/trunk/docs/security-9.html	Tue Aug 25 21:16:50 2026	(r1937456)
+++ tomcat/site/trunk/docs/security-9.html	Tue Aug 25 21:32:15 2026	(r1937457)
@@ -39,6 +39,85 @@
     <ul><li><a href="#Fixed_in_Apache_Tomcat_9.0.121">Fixed in Apache Tomcat 9.0.121</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.120">Fixed in Apache Tomcat 9.0.120</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.119">Fixed in Apache Tomcat 9.0.119</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.118">Fixed in Apache Tomcat 9.0.118</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.117">Fixed in Apache Tomcat 9.0.117</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.116">Fixed in Apache Tomcat 9.0.116</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.115">Fixed in Apache Tomcat 9.0.115</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.113">Fixed in Apache Tomcat 9.0.113</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.110">Fixed in Apache Tomcat 9.0.110</a></li><li><a href="#Fixed_in_Apa
 che_Tomcat_9.0.109">Fixed in Apache Tomcat 9.0.109</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.108">Fixed in Apache Tomcat 9.0.108</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.107">Fixed in
  Apache Tomcat 9.0.107</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.106">Fixed in Apache Tomcat 9.0.106</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.105">Fixed in Apache Tomcat 9.0.105</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.104">Fixed in Apache Tomcat 9.0.104</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.102">Fixed in Apache Tomcat 9.0.102</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.99">Fixed in Apache Tomcat 9.0.99</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.98">Fixed in Apache Tomcat 9.0.98</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.97">Fixed in Apache Tomcat 9.0.97</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.96">Fixed in Apache Tomcat 9.0.96</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.90">Fixed in Apache Tomcat 9.0.90</a></li><li><a href="
 #Fixed_in_Apache_Tomcat_9.0.86">Fixed in Apache Tomcat 9.0.86</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.83">Fixed in Apache Tomcat 9.0.83</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.81">
 Fixed in Apache Tomcat 9.0.81</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.80">Fixed in Apache Tomcat 9.0.80</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.75">Fixed in Apache Tomcat 9.0.75</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.74">Fixed in Apache Tomcat 9.0.74</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.72">Fixed in Apache Tomcat 9.0.72</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.71">Fixed in Apache Tomcat 9.0.71</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.69">Fixed in Apache Tomcat 9.0.69</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.68">Fixed in Apache Tomcat 9.0.68</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.65">Fixed in Apache Tomcat 9.0.65</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.63">Fixed in Apache Tomcat 9.0.63</a></li><li><a href="#
 Fixed_in_Apache_Tomcat_9.0.62">Fixed in Apache Tomcat 9.0.62</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.58">Fixed in Apache Tomcat 9.0.58</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.54">F
 ixed in Apache Tomcat 9.0.54</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.48">Fixed in Apache Tomcat 9.0.48</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.46">Fixed in Apache Tomcat 9.0.46</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.45">Fixed in Apache Tomcat 9.0.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.44">Fixed in Apache Tomcat 9.0.44</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.43">Fixed in Apache Tomcat 9.0.43</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.40">Fixed in Apache Tomcat 9.0.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.38">Fixed in Apache Tomcat 9.0.38</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.37">Fixed in Apache Tomcat 9.0.37</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.36">Fixed in Apache Tomcat 9.0.36</a></li><li><a href="#F
 ixed_in_Apache_Tomcat_9.0.35">Fixed in Apache Tomcat 9.0.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.31">Fixed in Apache Tomcat 9.0.31</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.30">Fi
 xed in Apache Tomcat 9.0.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.29">Fixed in Apache Tomcat 9.0.29</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.21">Fixed in Apache Tomcat 9.0.21</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.20">Fixed in Apache Tomcat 9.0.20</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.19">Fixed in Apache Tomcat 9.0.19</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.16">Fixed in Apache Tomcat 9.0.16</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.12">Fixed in Apache Tomcat 9.0.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.10">Fixed in Apache Tomcat 9.0.10</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.9">Fixed in Apache Tomcat 9.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.8">Fixed in Apache Tomcat 9.0.8</a></li><li><a href="#Fixed_
 in_Apache_Tomcat_9.0.5">Fixed in Apache Tomcat 9.0.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.2">Fixed in Apache Tomcat 9.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.1">Fixed in Apa
 che Tomcat 9.0.1</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M22">Fixed in Apache Tomcat 9.0.0.M22</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M21">Fixed in Apache Tomcat 9.0.0.M21</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M19">Fixed in Apache Tomcat 9.0.0.M19</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M18">Fixed in Apache Tomcat 9.0.0.M18</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M17">Fixed in Apache Tomcat 9.0.0.M17</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M15">Fixed in Apache Tomcat 9.0.0.M15</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M13">Fixed in Apache Tomcat 9.0.0.M13</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M10">Fixed in Apache Tomcat 9.0.0.M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M8">Fixed in Apache
  Tomcat 9.0.0.M8</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M3">Fixed in Apache Tomcat 9.0.0.M3</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in Tomcat</a></li></u
 l>
   </div><h3 id="Fixed_in_Apache_Tomcat_9.0.121"><span class="pull-right">2026-08-18</span> Fixed in Apache Tomcat 9.0.121</h3><div class="text">
 
+    <p><strong>Low: Authenticated WebSocket session survives end of HTTP
+       session</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73180" rel="nofollow">CVE-2026-73180</a></p>
+
+    <p>If the session ID for an authenticated HTTP session was changed after a
+       WebSocket connection had been established under that authenticated HTTP
+       session, the WebSokcet session would not be closed as required by the
+       Jakarta WebSocket specification when the HTTP session ended.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/4b41a73a2f1a16647d7444ad6ee87d41a3ec414b">4b41a73a</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 30 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.0-M1 to 9.0.120</p>
+
+    <p><strong>Important: DoS via allocation leak in HTTP/2 backlog tracking
+       when a stream is reset</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-68763" rel="nofollow">CVE-2026-68763</a></p>
+
+    <p>An allocation leak in the HTTP/2 backlog tracking when a stream was reset
+       could be manipulated to trigger a denial of service.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/0747dd58cc631f90e044df246bd2ede6e2b48250">0747dd58</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 16 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.39 to 9.0.120</p>
+
+    <p><strong>Important: Principal lookup could fail open in some
+       cases</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-68569" rel="nofollow">CVE-2026-68569</a></p>
+
+    <p>For some authentication methods (e.g. CLIENT-CERT, SPNEGO), a user would
+       be authenticated even if the user did not exist in the
+       DataSourceRealm and JDBCRealm.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/8efd51f061c026f6339bfa4fe4ef919a04ef130a">8efd51f0</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 16 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.0.M1 to 9.0.120</p>
+
+    <p><strong>Low: Redirect after FORM authentication may bypass method
+       specific constraints</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-68525" rel="nofollow">CVE-2026-68525</a></p>
+
+    <p>The FORM authentication process allowed the bypassing of a security
+       constraint that limited user access to a resource POST but not GET.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/32f0c38526b4e655ff0c17cd97afedefc624fe43">32f0c385</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 15 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Low: Servlet role references can bypass declarative role
+       constraints</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66422" rel="nofollow">CVE-2026-66422</a></p>
+
+    <p><code>security-role-ref</code> definitions were incorrectly used as role
+       aliases within the Realm in additional to the correct usage with
+       <code>Request.isUserInRole()</code>.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/bd05d5ced387da0c967bb232f7e3cd57685d2a7b">bd05d5ce</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.25 to 9.0.120</p>
+
     <p><strong>Low: DoS in WebSocket chat example</strong>
        <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66299" rel="nofollow">CVE-2026-66299</a></p>
 
@@ -57,6 +136,85 @@
        Users who followed the security guidance to remove the examples web
        application are not affected.</p>
 
+    <p><strong>Important: RewriteValve [N] restarts at the second rule and may
+       bypass access control</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65927" rel="nofollow">CVE-2026-65927</a></p>
+
+    <p>An off-by-one error impacting the [N] flag on the rewrite valves caused
+       rewrite processing to restart at the second rule rather than the first
+       rule.</p>
+
+    <p>This was fixed with commits
+       <a href="https://github.com/apache/tomcat/commit/ffa86dc683645f784e36ec87236d51ea866dcadf">ffa86dc6</a> and
+       <a href="https://github.com/apache/tomcat/commit/b477537e68acfcaa7220f90b512bf8a72bf237dc">b477537e</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.0-M1 to 9.0.120</p>
+
+    <p><strong>Low: Limited replay attack possible with DIGEST
+       authentication</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65905" rel="nofollow">CVE-2026-65905</a></p>
+
+    <p>If, before windowSize requests had been made, a client made a DIGEST
+       authenticated request with a nonceCount on the upper boundary of the
+       replay window then that request was replayable once only while the
+       associated nonceCount remained within the replay window.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/a31181af45e494b6035575519f6d1d33875f050d">a31181af</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.0.M1 to 9.0.120</p>
+
+    <p><strong>Moderate: HTTP/2 no-authority bypass of strict SNI
+       validation</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65637" rel="nofollow">CVE-2026-65637</a></p>
+
+    <p>The fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32990" rel="nofollow">CVE-2026-32990</a> was incomplete.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/b823e88da077f5fa973e34d72359bded9f621e3c">b823e88d</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.115 to 9.0.120</p>
+
+    <p><strong>Low: TOCTOU when setting specific permissions for Unix Domain
+       Sockets</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65183" rel="nofollow">CVE-2026-65183</a></p>
+
+    <p>A race condition when creating a Unix Domain Socket allowed an
+       unauthorised local user to access the Unix Domain Socket.</p>
+
+    <p>This was fixed with commits
+       <a href="https://github.com/apache/tomcat/commit/0206022f3aae65c5e0f23334b080849fdaaef444">0206022f</a> and
+       <a href="https://github.com/apache/tomcat/commit/07e1b7d3da47a97d2861116f0ba5dd2b4018d256">07e1b7d3</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 3 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.42 to 9.0.120</p>
+
+    <p><strong>Important: Security constraint bypass</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65182" rel="nofollow">CVE-2026-65182</a></p>
+
+    <p>The security constraint processing enabled a security constraint bypass
+       if a constraint for a longer path was specified before a more restrictive
+       constraint for a shorter sub-path.</p>
+
+    <p>This was fixed with commit
+       <a href="https://github.com/apache/tomcat/commit/b2c56ec8f20c66773a1a813034ffcdb60841f1cf">b2c56ec8</a>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.0.M1 to 9.0.120</p>
+
   </div><h3 id="Fixed_in_Apache_Tomcat_9.0.120"><span class="pull-right">2026-07-07</span> Fixed in Apache Tomcat 9.0.120</h3><div class="text">
 
     <p><strong>Low: EncryptInterceptor requirements not clearly

Modified: tomcat/site/trunk/xdocs/security-10.xml
==============================================================================
--- tomcat/site/trunk/xdocs/security-10.xml	Tue Aug 25 21:16:50 2026	(r1937456)
+++ tomcat/site/trunk/xdocs/security-10.xml	Tue Aug 25 21:32:15 2026	(r1937457)
@@ -64,6 +64,85 @@
        fix for these issues, version 10.1.58 is not included in the list of 
        affected versions.</i></p>
 
+    <p><strong>Low: Authenticated WebSocket session survives end of HTTP
+       session</strong>
+       <cve>CVE-2026-73180</cve></p>
+
+    <p>If the session ID for an authenticated HTTP session was changed after a
+       WebSocket connection had been established under that authenticated HTTP
+       session, the WebSokcet session would not be closed as required by the
+       Jakarta WebSocket specification when the HTTP session ended.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="83427cbdb92ca41244dc3d242ca4308ed8ade7d3"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 30 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Important: DoS via allocation leak in HTTP/2 backlog tracking
+       when a stream is reset</strong>
+       <cve>CVE-2026-68763</cve></p>
+
+    <p>An allocation leak in the HTTP/2 backlog tracking when a stream was reset
+       could be manipulated to trigger a denial of service.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="19d40615620fe145e88536e2bd63c5f01077c253"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 16 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Important: Principal lookup could fail open in some
+       cases</strong>
+       <cve>CVE-2026-68569</cve></p>
+
+    <p>For some authentication methods (e.g. CLIENT-CERT, SPNEGO), a user would
+       be authenticated even if the user did not exist in the
+       DataSourceRealm.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="3ff06ceb984edc2a3c9e0161b01e833c5e50ed4f"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 16 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Low: Redirect after FORM authentication may bypass method
+       specific constraints</strong>
+       <cve>CVE-2026-68525</cve></p>
+
+    <p>The FORM authentication process allowed the bypassing of a security
+       constraint that limited user access to a resource POST but not GET.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="58123aa468a20e2a079b7e0c68a4009e2475c098"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 15 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Low: Servlet role references can bypass declarative role
+       constraints</strong>
+       <cve>CVE-2026-66422</cve></p>
+
+    <p><code>security-role-ref</code> definitions were incorrectly used as role
+       aliases within the Realm in additional to the correct usage with
+       <code>Request.isUserInRole()</code>.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="49506f6d5ad7cdef211ce1a4026a29183b3df5c7"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
     <p><strong>Low: DoS in WebSocket chat example</strong>
        <cve>CVE-2026-66299</cve></p>
 
@@ -82,6 +161,84 @@
        Users who followed the security guidance to remove the examples web
        application are not affected.</p>
 
+    <p><strong>Important: RewriteValve [N] restarts at the second rule and may
+       bypass access control</strong>
+       <cve>CVE-2026-65927</cve></p>
+
+    <p>An off-by-one error impacting the [N] flag on the rewrite valves caused
+       rewrite processing to restart at the second rule rather than the first
+       rule.</p>
+
+    <p>This was fixed with commits
+       <hashlink hash="3097902177a041a93476a036b9c8419b25d5cc0d"/> and
+       <hashlink hash="7d2ae3952a39db5790dcfd36e5d79c75570a20ee"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Low: Limited replay attack possible with DIGEST
+       authentication</strong>
+       <cve>CVE-2026-65905</cve></p>
+
+    <p>If, before windowSize requests had been made, a client made a DIGEST
+       authenticated request with a nonceCount on the upper boundary of the
+       replay window then that request was replayable once only while the
+       associated nonceCount remained within the replay window.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="1c1a583ba57092206f77c375f45da12c99fb141d"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Moderate: HTTP/2 no-authority bypass of strict SNI
+       validation</strong>
+       <cve>CVE-2026-65637</cve></p>
+
+    <p>The fix for <cve>CVE-2026-32990</cve> was incomplete.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="40012414df828a56126f76a7339669c7c919aae7"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.53 to 10.1.57</p>
+
+    <p><strong>Low: TOCTOU when setting specific permissions for Unix Domain
+       Sockets</strong>
+       <cve>CVE-2026-65183</cve></p>
+
+    <p>A race condition when creating a Unix Domain Socket allowed an
+       unauthorised local user to access the Unix Domain Socket.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="d8bcec9a30788fd887f33890b77ae1b8cd5f1f7e"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 3 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Important: Security constraint bypass</strong>
+       <cve>CVE-2026-65182</cve></p>
+
+    <p>The security constraint processing enabled a security constraint bypass
+       if a constraint for a longer path was specified before a more restrictive
+       constraint for a shorter sub-path.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="b79752d2a8578d94743e2a95c50af297f780c0df"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
   </section>
   
   <section name="Fixed in Apache Tomcat 10.1.57" rtext="2026-07-07">

Modified: tomcat/site/trunk/xdocs/security-11.xml
==============================================================================
--- tomcat/site/trunk/xdocs/security-11.xml	Tue Aug 25 21:16:50 2026	(r1937456)
+++ tomcat/site/trunk/xdocs/security-11.xml	Tue Aug 25 21:32:15 2026	(r1937457)
@@ -52,6 +52,85 @@
 
   <section name="Fixed in Apache Tomcat 11.0.25" rtext="2026-08-18">
 
+    <p><strong>Low: Authenticated WebSocket session survives end of HTTP
+       session</strong>
+       <cve>CVE-2026-73180</cve></p>
+
+    <p>If the session ID for an authenticated HTTP session was changed after a
+       WebSocket connection had been established under that authenticated HTTP
+       session, the WebSokcet session would not be closed as required by the
+       Jakarta WebSocket specification when the HTTP session ended.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="e617a5d483b78851d289ca8dc1d68c49b541b419"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 30 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Important: DoS via allocation leak in HTTP/2 backlog tracking
+       when a stream is reset</strong>
+       <cve>CVE-2026-68763</cve></p>
+
+    <p>An allocation leak in the HTTP/2 backlog tracking when a stream was reset
+       could be manipulated to trigger a denial of service.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="2a5ec806971627943db18601203129d9c58d959f"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 16 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Important: Principal lookup could fail open in some
+       cases</strong>
+       <cve>CVE-2026-68569</cve></p>
+
+    <p>For some authentication methods (e.g. CLIENT-CERT, SPNEGO), a user would
+       be authenticated even if the user did not exist in the
+       DataSourceRealm.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="790d6e2c3b4cd201a1fa556a23d5b7504dee18ad"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 16 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Low: Redirect after FORM authentication may bypass method
+       specific constraints</strong>
+       <cve>CVE-2026-68525</cve></p>
+
+    <p>The FORM authentication process allowed the bypassing of a security
+       constraint that limited user access to a resource POST but not GET.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="10d048e16034ddf12055e0cede0da05b15c823b8"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 15 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Low: Servlet role references can bypass declarative role
+       constraints</strong>
+       <cve>CVE-2026-66422</cve></p>
+
+    <p><code>security-role-ref</code> definitions were incorrectly used as role
+       aliases within the Realm in additional to the correct usage with
+       <code>Request.isUserInRole()</code>.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="2c2c510ab10ae7796de6c6f7b70abae85c99d30d"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
     <p><strong>Low: DoS in WebSocket chat example</strong>
        <cve>CVE-2026-66299</cve></p>
 
@@ -70,6 +149,84 @@
        Users who followed the security guidance to remove the examples web
        application are not affected.</p>
 
+    <p><strong>Important: RewriteValve [N] restarts at the second rule and may
+       bypass access control</strong>
+       <cve>CVE-2026-65927</cve></p>
+
+    <p>An off-by-one error impacting the [N] flag on the rewrite valves caused
+       rewrite processing to restart at the second rule rather than the first
+       rule.</p>
+
+    <p>This was fixed with commits
+       <hashlink hash="bce83410ffb1542752d52b536257e81a5c8dfcb8"/> and
+       <hashlink hash="b80929d65be774dc90e378acdda2d16949d1e5f3"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Low: Limited replay attack possible with DIGEST
+       authentication</strong>
+       <cve>CVE-2026-65905</cve></p>
+
+    <p>If, before windowSize requests had been made, a client made a DIGEST
+       authenticated request with a nonceCount on the upper boundary of the
+       replay window then that request was replayable once only while the
+       associated nonceCount remained within the replay window.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="c5f94ad1726e8399b77eb3fd69c811c1103894d6"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Moderate: HTTP/2 no-authority bypass of strict SNI
+       validation</strong>
+       <cve>CVE-2026-65637</cve></p>
+
+    <p>The fix for <cve>CVE-2026-32990</cve> was incomplete.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="8639b20f045c88f356b887204f52e897399f0de7"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.20 to 11.0.24</p>
+
+    <p><strong>Low: TOCTOU when setting specific permissions for Unix Domain
+       Sockets</strong>
+       <cve>CVE-2026-65183</cve></p>
+
+    <p>A race condition when creating a Unix Domain Socket allowed an
+       unauthorised local user to access the Unix Domain Socket.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="4fb4523d70258614a00e7501ae0fdf3cdcbc2470"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 3 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
+    <p><strong>Important: Security constraint bypass</strong>
+       <cve>CVE-2026-65182</cve></p>
+
+    <p>The security constraint processing enabled a security constraint bypass
+       if a constraint for a longer path was specified before a more restrictive
+       constraint for a shorter sub-path.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="8bafd79a3b54684e80e9cb1bafd4746aede7d3f5"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 11.0.0-M1 to 11.0.24</p>
+
   </section>
   
   <section name="Fixed in Apache Tomcat 11.0.24" rtext="2026-07-08">

Modified: tomcat/site/trunk/xdocs/security-9.xml
==============================================================================
--- tomcat/site/trunk/xdocs/security-9.xml	Tue Aug 25 21:16:50 2026	(r1937456)
+++ tomcat/site/trunk/xdocs/security-9.xml	Tue Aug 25 21:32:15 2026	(r1937457)
@@ -52,6 +52,85 @@
 
   <section name="Fixed in Apache Tomcat 9.0.121" rtext="2026-08-18">
 
+    <p><strong>Low: Authenticated WebSocket session survives end of HTTP
+       session</strong>
+       <cve>CVE-2026-73180</cve></p>
+
+    <p>If the session ID for an authenticated HTTP session was changed after a
+       WebSocket connection had been established under that authenticated HTTP
+       session, the WebSokcet session would not be closed as required by the
+       Jakarta WebSocket specification when the HTTP session ended.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="4b41a73a2f1a16647d7444ad6ee87d41a3ec414b"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 30 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.0-M1 to 9.0.120</p>
+
+    <p><strong>Important: DoS via allocation leak in HTTP/2 backlog tracking
+       when a stream is reset</strong>
+       <cve>CVE-2026-68763</cve></p>
+
+    <p>An allocation leak in the HTTP/2 backlog tracking when a stream was reset
+       could be manipulated to trigger a denial of service.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="0747dd58cc631f90e044df246bd2ede6e2b48250"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 16 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.39 to 9.0.120</p>
+
+    <p><strong>Important: Principal lookup could fail open in some
+       cases</strong>
+       <cve>CVE-2026-68569</cve></p>
+
+    <p>For some authentication methods (e.g. CLIENT-CERT, SPNEGO), a user would
+       be authenticated even if the user did not exist in the
+       DataSourceRealm and JDBCRealm.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="8efd51f061c026f6339bfa4fe4ef919a04ef130a"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 16 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.0.M1 to 9.0.120</p>
+
+    <p><strong>Low: Redirect after FORM authentication may bypass method
+       specific constraints</strong>
+       <cve>CVE-2026-68525</cve></p>
+
+    <p>The FORM authentication process allowed the bypassing of a security
+       constraint that limited user access to a resource POST but not GET.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="32f0c38526b4e655ff0c17cd97afedefc624fe43"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 15 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 10.1.0-M1 to 10.1.57</p>
+
+    <p><strong>Low: Servlet role references can bypass declarative role
+       constraints</strong>
+       <cve>CVE-2026-66422</cve></p>
+
+    <p><code>security-role-ref</code> definitions were incorrectly used as role
+       aliases within the Realm in additional to the correct usage with
+       <code>Request.isUserInRole()</code>.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="bd05d5ced387da0c967bb232f7e3cd57685d2a7b"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.25 to 9.0.120</p>
+
     <p><strong>Low: DoS in WebSocket chat example</strong>
        <cve>CVE-2026-66299</cve></p>
 
@@ -70,6 +149,85 @@
        Users who followed the security guidance to remove the examples web
        application are not affected.</p>
 
+    <p><strong>Important: RewriteValve [N] restarts at the second rule and may
+       bypass access control</strong>
+       <cve>CVE-2026-65927</cve></p>
+
+    <p>An off-by-one error impacting the [N] flag on the rewrite valves caused
+       rewrite processing to restart at the second rule rather than the first
+       rule.</p>
+
+    <p>This was fixed with commits
+       <hashlink hash="ffa86dc683645f784e36ec87236d51ea866dcadf"/> and
+       <hashlink hash="b477537e68acfcaa7220f90b512bf8a72bf237dc"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.0-M1 to 9.0.120</p>
+
+    <p><strong>Low: Limited replay attack possible with DIGEST
+       authentication</strong>
+       <cve>CVE-2026-65905</cve></p>
+
+    <p>If, before windowSize requests had been made, a client made a DIGEST
+       authenticated request with a nonceCount on the upper boundary of the
+       replay window then that request was replayable once only while the
+       associated nonceCount remained within the replay window.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="a31181af45e494b6035575519f6d1d33875f050d"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.0.M1 to 9.0.120</p>
+
+    <p><strong>Moderate: HTTP/2 no-authority bypass of strict SNI
+       validation</strong>
+       <cve>CVE-2026-65637</cve></p>
+
+    <p>The fix for <cve>CVE-2026-32990</cve> was incomplete.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="b823e88da077f5fa973e34d72359bded9f621e3c"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.115 to 9.0.120</p>
+
+    <p><strong>Low: TOCTOU when setting specific permissions for Unix Domain
+       Sockets</strong>
+       <cve>CVE-2026-65183</cve></p>
+
+    <p>A race condition when creating a Unix Domain Socket allowed an
+       unauthorised local user to access the Unix Domain Socket.</p>
+
+    <p>This was fixed with commits
+       <hashlink hash="0206022f3aae65c5e0f23334b080849fdaaef444"/> and
+       <hashlink hash="07e1b7d3da47a97d2861116f0ba5dd2b4018d256"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 3 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.42 to 9.0.120</p>
+
+    <p><strong>Important: Security constraint bypass</strong>
+       <cve>CVE-2026-65182</cve></p>
+
+    <p>The security constraint processing enabled a security constraint bypass
+       if a constraint for a longer path was specified before a more restrictive
+       constraint for a shorter sub-path.</p>
+
+    <p>This was fixed with commit
+       <hashlink hash="b2c56ec8f20c66773a1a813034ffcdb60841f1cf"/>.</p>
+
+    <p>This issue was reported to the Tomcat security team on 13 July 2026.
+       The issue was made public on 25 August 2026.</p>
+
+    <p>Affects: 9.0.0.M1 to 9.0.120</p>
+
   </section>
   
   <section name="Fixed in Apache Tomcat 9.0.120" rtext="2026-07-07">
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.