Information on source package tomcat11

Available versions

ReleaseVersion
trixie11.0.15-1~deb13u1
trixie (security)11.0.22-1~deb13u1
forky11.0.22-2
sid11.0.22-2

Resolved issues

BugDescription
CVE-2026-43515Improper Authorization vulnerability when multiple method constraints ...
CVE-2026-43514Observable Timing Discrepancy vulnerabilitywhen comparing AJP secret i ...
CVE-2026-43513Improper Handling of Case Sensitivity vulnerability in LockOutRealm in ...
CVE-2026-43512DEPRECATED: Authentication Bypass Issues vulnerability in digest authe ...
CVE-2026-42498Exposure of HTTP Authentication Header to unexpected hosts during WebS ...
CVE-2026-41293Improper Input Validation vulnerability in Apache Tomcat. This issue ...
CVE-2026-41284Allocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-34500CLIENT_CERT authentication does not fail as expected for some scenario ...
CVE-2026-34487Insertion of Sensitive Information into Log File vulnerability in the ...
CVE-2026-34486Missing Encryption of Sensitive Data vulnerability in Apache Tomcat du ...
CVE-2026-34483Improper Encoding or Escaping of Output vulnerability in the JsonAcces ...
CVE-2026-32990Improper Input Validation vulnerability in Apache Tomcat due to an inc ...
CVE-2026-29146Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor wit ...
CVE-2026-29145CLIENT_CERT authentication does not fail as expected for some scenario ...
CVE-2026-29129Configured cipher preference order not preserved vulnerability in Apac ...
CVE-2026-25854Occasional URL redirection to untrusted Site ('Open Redirect') vulnera ...
CVE-2026-24880Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...
CVE-2026-24734Improper Input Validation vulnerability in Apache Tomcat Native, Apach ...
CVE-2026-24733Improper Input Validation vulnerability in Apache Tomcat. Tomcat did ...
CVE-2025-66614Improper Input Validation vulnerability. This issue affects Apache To ...
CVE-2025-61795Improper Resource Shutdown or Release vulnerability in Apache Tomcat. ...
CVE-2025-55754Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...
CVE-2025-55752Relative Path Traversal vulnerability in Apache Tomcat. The fix for b ...
CVE-2025-55668Session Fixation vulnerability in Apache Tomcat via rewrite valve. Th ...
CVE-2025-53506Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an ...
CVE-2025-52520For some unlikely configurations of multipart upload, an Integer Overf ...
CVE-2025-49125Authentication Bypass Using an Alternate Path or Channel vulnerability ...
CVE-2025-49124Untrusted Search Path vulnerability in Apache Tomcat installer for Win ...
CVE-2025-48989Improper Resource Shutdown or Release vulnerability in Apache Tomcat m ...
CVE-2025-48988Allocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2025-48976Allocation of resources for multipart headers with insufficient limits ...
CVE-2025-46701Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's ...
CVE-2025-31651Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...
CVE-2025-31650Improper Input Validation vulnerability in Apache Tomcat. Incorrect er ...

Security announcements

DSA / DLADescription
DSA-6329-1tomcat11 - security update
DSA-6121-1tomcat11 - security update

Search for package or bug name: Reporting problems