[DSA 6328-1] tomcat10 security update
Markus Koschany <[email protected]> Mon, 8 Jun 2026 12:57:54 +0000
| Newsgroups | gmane.linux.debian.user.security.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6328-1 [email protected] https://www.debian.org/security/ Markus Koschany June 08, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tomcat10 CVE ID : CVE-2026-24880 CVE-2026-25854 CVE-2026-29129 CVE-2026-29145 CVE-2026-29146 CVE-2026-32990 CVE-2026-34483 CVE-2026-34487 CVE-2026-34500 CVE-2026-41284 CVE-2026-41293 CVE-2026-42498 CVE-2026-43512 CVE-2026-43513 CVE-2026-43514 CVE-2026-43515 Multiple security vulnerabilities have been discovered in Tomcat 10, a Java based web server, servlet and JSP engine which may result in a denial of service, authentication bypass or the disclosure of sensitive information. Although we are not aware of any problems, new upstream versions may introduce new options, limits or code changes which may or may not affect your existing web applications. We recommend to consult the Tomcat 10 documentation for further information. For the oldstable distribution (bookworm), these problems have been fixed in version 10.1.55-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 10.1.55-1~deb13u1. We recommend that you upgrade your tomcat10 packages. For the detailed security status of tomcat10 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/tomcat10 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmomtKFfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7 UeQslg//eJAcasr5bsLEyDpJ61EzUdMPJqNuXeVOFk7xwNAkAEN/tHdZtFjeUzzL 5yodji95t0OmzMPd3wYuMuGVVlByfiY8QnFrUvGeGh16Z3iW6OAbZDK/RIO8J4LF WwFVOigeekw8ZKEJA+KAzlX8SEVQ8DQx+y/PGyoPe5K1O30yVCQMbBY9zcQfzFe6 PsibTi+ZjKZSE5UUKtHFY/9ujODmSIv4XZ30yptibU9OD0HmAJkMUVbZWyr1foTS C8pDf/+24umt5VCtV0pLw7azfzLyEKtUhunCHrRw2UcV3I1WHkgC/61mTc33+XTK TfDWFpcUxTa7dj9UzpNN3Dw8/vkwCP6L3uS7ZBDY6HDh7+EjGTdWLnHnXgaKA8oe JuJ32xvZo9HrQdmPRdJC1Poil/5cssssUBkjU7RNKjLAKILqy7FWLmTvpB+0ptv4 c9BeBDsyqbhf4s/tpBEfJwM5LCxq3V9iL8nK2Rvn02kbkYI+Z6uvcj7E1vd0tZYi L94tXVXO/U2o2J+xwVGw4ZgI+E1mGUHgda/JFa+3Kr4Ts/fNzfOKHjJmAnOfUzPd 22k5Ewcy0a7c1uGuNFNqA851TsQ52eyYuyVN2fzE1GHPt2XaLlVexKRHrnGNGHTp RxEThbwNgJvczPbJ2LABFNez2mjQLkZHsMQE5VFq3NSiqyhDAY0= =WgrD -----END PGP SIGNATURE-----