{"id":"MGASA-2026-0376","summary":"Updated tomcat packages fix security vulnerabilities","details":"Incorrect URL decoding in RewriteValve may allow security control\nbypass. (CVE-2026-59083)\nEncryptInterceptor requirements not clearly documented. (CVE-2026-59084)\nDoS via WebSocket chat example. (CVE-2026-66299)\nBypass longest prefix security constraint. (CVE-2026-65182)\nTOCTOU when setting specific permissions for Unix Domain Sockets.\n(CVE-2026-65183)\nHTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix\nincomplete. (CVE-2026-65637)\nLimited replay attack possible with DIGEST authentication.\n(CVE-2026-65905)\nRewriteValve [N] restarts at the second rule and may bypass access\ncontrol. (CVE-2026-65927)\nServlet role references can bypass declarative role constraints.\n(CVE-2026-66422)\nRedirect after FORM auth may bypass method specific constraints.\n(CVE-2026-68525)\nPrincipal lookup can fail open in some cases. (CVE-2026-68569)\nDoS via allocation leak in HTTP/2 backlog tracking when a stream is\nreset. (CVE-2026-68763)\nAuthenticated WebSocket session survives end of HTTP session.\n(CVE-2026-73180)\n","modified":"2026-09-04T18:11:25.978847759Z","published":"2026-09-04T17:53:22Z","upstream":["CVE-2026-59083","CVE-2026-59084","CVE-2026-65182","CVE-2026-65183","CVE-2026-65637","CVE-2026-65905","CVE-2026-65927","CVE-2026-66299","CVE-2026-66422","CVE-2026-68525","CVE-2026-68569","CVE-2026-68763","CVE-2026-73180"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0376.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35927"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/07/14/7"},{"type":"WEB","url":"https://lists.apache.org/thread/3g63zos2gkjo5vgnrk8kxmosv47w6wbq"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/07/14/8"},{"type":"WEB","url":"https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/07/28/25"},{"type":"WEB","url":"https://lists.apache.org/thread/8owczcc1o8qw1rxmg9gvfk4w2jnh4l5k"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/26/1"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/26/2"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/26/3"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/26/4"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/26/5"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/26/6"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/26/7"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/26/8"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/26/9"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/26/10"}],"affected":[{"package":{"name":"tomcat","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/tomcat?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.121-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0376.json"}},{"package":{"name":"tomcat","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/tomcat?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.121-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0376.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}