{"id":"CLSA-2026-1779374454","summary":"Fix of 7 CVEs","details":"   * SECURITY UPDATE: multiple security fixes\n     - debian/patches/CVE-2026-41284.patch: add a configurable\n       maxRequestBodySize init-param to the WebDAV servlet to bound\n       LOCK/PROPFIND XML request bodies; reject oversized bodies with\n       413 Request Entity Too Long. Includes the upstream\n       BoundedByteArrayOutputStream helper and associated tests\n     - CVE-2026-41284\n     - debian/patches/CVE-2026-41293.patch: filter invalid HTTP/2 header\n       names in HpackDecoder / HPackHuffman / Stream / Http2Parser using\n       a new HttpParser.isToken-based check; folds upstream follow-up\n       (HttpParser i\u003e32 hex/decimal fix, additional LocalStrings keys,\n       HpackHuffman field-name branch simplification) and ships the new\n       TestHPackHuffman / TestHttp2Section_8_2 tests.\n     - debian/patches/CVE-2026-41293-tests.patch: adapt\n       TestHttp2Section_8_2 to the 9.0.31 readFrame(boolean) signature\n     - CVE-2026-41293\n     - debian/patches/CVE-2026-42498.patch: strip Authorization and\n       Proxy-Authorization headers from WebSocket client userProperties\n       after the proxy CONNECT, HTTP redirect, and successful upgrade\n       paths so credentials are not leaked to redirect or proxy targets\n     - CVE-2026-42498\n     - debian/patches/CVE-2026-43512.patch: fix DIGEST authentication\n       handling of unknown users and users with a null password so they\n       cannot authenticate; adds regression tests to\n       TestDigestAuthenticator\n     - CVE-2026-43512\n     - debian/patches/CVE-2026-43513.patch: add caseSensitive attribute\n       to LockOutRealm and route usernames through a null-safe\n       normalizeUsername helper so case-insensitive realms cannot be\n       brute-forced by varying the case of the username. Folds the\n       upstream Coverity NPE follow-up and adds the new TestLockoutRealm\n       JUnit tests\n     - CVE-2026-43513\n     - debian/patches/CVE-2026-43514.patch: switch the AJP secret\n       comparison in AjpProcessor to a constant-time comparison using\n       the new ConstantTime utility; includes the upstream\n       ByteChunk start-offset follow-up\n     - CVE-2026-43514\n     - debian/patches/CVE-2026-43515.patch: ensure RealmBase finds all\n       matching extension-based security constraints by moving the match\n       bookkeeping inside the inner extension-pattern loop; adds the\n       upstream TestRealmBase.testUncoveredMethods regression test and\n       a TesterRequest.getRequestPathMB() helper\n     - CVE-2026-43515","modified":"2026-06-04T09:45:33.309402654Z","published":"2026-05-21T14:41:06Z","upstream":["CVE-2026-41284","CVE-2026-41293","CVE-2026-42498","CVE-2026-43512","CVE-2026-43513","CVE-2026-43514","CVE-2026-43515"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/ubuntu20.04els/CLSA-2026-1779374454.html"}],"affected":[{"package":{"name":"libtomcat9-embed-java","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/libtomcat9-embed-java?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1ubuntu0.9+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1779374454.json"}},{"package":{"name":"libtomcat9-java","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/libtomcat9-java?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1ubuntu0.9+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1779374454.json"}},{"package":{"name":"tomcat9","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/tomcat9?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1ubuntu0.9+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1779374454.json"}},{"package":{"name":"tomcat9-admin","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/tomcat9-admin?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1ubuntu0.9+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1779374454.json"}},{"package":{"name":"tomcat9-common","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/tomcat9-common?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1ubuntu0.9+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1779374454.json"}},{"package":{"name":"tomcat9-docs","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/tomcat9-docs?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1ubuntu0.9+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1779374454.json"}},{"package":{"name":"tomcat9-examples","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/tomcat9-examples?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1ubuntu0.9+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1779374454.json"}},{"package":{"name":"tomcat9-user","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/tomcat9-user?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1ubuntu0.9+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1779374454.json"}}],"schema_version":"1.7.5"}