[DSA 6329-1] tomcat11 security update
Markus Koschany <[email protected]> Mon, 8 Jun 2026 13:00:58 +0000
| Newsgroups | gmane.linux.debian.user.security.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6329-1 [email protected] https://www.debian.org/security/ Markus Koschany June 08, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tomcat11 CVE ID : CVE-2026-24734 CVE-2026-24880 CVE-2026-25854 CVE-2026-29129 CVE-2026-29145 CVE-2026-29146 CVE-2026-32990 CVE-2026-34483 CVE-2026-34487 CVE-2026-34500 CVE-2026-41284 CVE-2026-41293 CVE-2026-42498 CVE-2026-43512 CVE-2026-43513 CVE-2026-43514 CVE-2026-43515 Multiple security vulnerabilities have been discovered in Tomcat 11, a Java based web server, servlet and JSP engine which may result in a denial of service, authentication bypass or the disclosure of sensitive information. Although we are not aware of any problems, new upstream versions may introduce new options, limits or code changes which may or may not affect your existing web applications. We recommend to consult the Tomcat 11 documentation for further information. For the stable distribution (trixie), these problems have been fixed in version 11.0.22-1~deb13u1. We recommend that you upgrade your tomcat11 packages. For the detailed security status of tomcat11 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/tomcat11 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmomtKVfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7 UeS8aBAAkRHBQSksEUcj+4/sCyMsFbX2EbjGu6m36o213mp/fVRgyYk7VvNH0PBG y/7/FRILF/0LiFlOXo/7jsOZm5VeQukCdTB8CCVaFi//kerjii+aBxZUCHWpe8Np F4BYRjYVp6J7/WRAoDPcZjNT1eDcOlmrbydCigm0JYfvqSycYHBdTaMwHQHCwM16 InL3ZB7EU3rcwxKwrY4SMHYrv1IE/1ZIX0QezCi/2RmD+X1aov4w4Uvmy+k/oocF mHPzDOkv2oyDJ3X6VnnJuTo7rJ7BBcyLF1SaXSk2D8YPAfjNNOrwjSUp4JA6TjKI ugLVHTTQtx9Le1f0nPHuyRXi7P11itD9gWOnLVso99ogPnp/oY9LRjnfCtw1LVyB 26ANPTLWPI40fvdGsPckKmA6j1ap3sCqvLsgOWAMVHpoI2BrGe8UzGRdjqIr9MHV F9twx9PT5hpqHptGbc60iWR7av/A4Rk8WVdZi/Nor64F+oiR2TALs/JZr6QUjvkm eTOuvpjmVGmqOjvpi9p43LRFSBSbjs3OsUtHX2655uYLUgcsFqn/NZMeuikjgUYk zlNvfCfzL6SFU0mziTK2JcOTn3t/wh1EzgAfdgxiBJ5F2z0jfIfGt5mKEP4GcswL kXNtiJVJ1kRucreUKSv9mp5s4pt1jIdQXT231b+uyFtgJkRgix8= =Z79r -----END PGP SIGNATURE-----