[CLSA-2026:1779968889] Fix of 7 CVEs
Type:
security
Severity:
Low
Release date:
2026-05-28 14:02:01 UTC
Description:
* SECURITY UPDATE: Authentication Bypass in digest authentication - debian/patches/CVE-2026-43512.patch: reject digest authentication attempts for unknown users in getDigest() - CVE-2026-43512 * SECURITY UPDATE: Account lockout bypass in LockOutRealm via case variation of user names - debian/patches/CVE-2026-43513.patch: add a caseSensitive attribute to LockOutRealm and treat user names case-insensitively by default - CVE-2026-43513 * SECURITY UPDATE: Observable timing discrepancy in AJP secret comparison - debian/patches/CVE-2026-43514.patch: add ConstantTime helper and switch the AJP secret comparison to a constant time algorithm - CVE-2026-43514 * SECURITY UPDATE: Improper authorisation when multiple method constraints define an HTTP method for the same extension - debian/patches/CVE-2026-43515.patch: evaluate findMethod() against every matching SecurityCollection rather than only the last one - CVE-2026-43515 * SECURITY UPDATE: Exposure of HTTP authorisation header to unexpected hosts during WebSocket authentication - debian/patches/CVE-2026-42498.patch: drop the cached Authorization header from userProperties before following a WebSocket upgrade redirect so it is not sent to the host named in Location - CVE-2026-42498 * SECURITY UPDATE: HTTP/2 header values were not validated for control characters and other illegal bytes - debian/patches/CVE-2026-41293.patch: validate field names and values in HpackDecoder and HPackHuffman using the new HttpParser isFieldVChar / isFieldContent tables - CVE-2026-41293 * SECURITY UPDATE: Allocation of resources without limits in WebDAV LOCK and PROPFIND request bodies - debian/patches/CVE-2026-41284.patch: read PROPFIND and LOCK bodies through a new BoundedByteArrayOutputStream limited by the new maxRequestBodySize init parameter (default 4096 bytes) - CVE-2026-41284
Updated packages:
  • libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els5_all.deb
    sha:2d969cfeb8f2d2e05570b2277745b4f528506ddf
  • libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els5_all.deb
    sha:8921f592921fc6989ead896f320808351b82d94d
  • tomcat9_9.0.31-1~deb10u12+tuxcare.els5_all.deb
    sha:17c9d875467153bd39659c057cd07fc2ec12e910
  • tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els5_all.deb
    sha:64215f5453cf59ad05b471bf461e7acf2875daba
  • tomcat9-common_9.0.31-1~deb10u12+tuxcare.els5_all.deb
    sha:6d9917abfeab96706638de832758695267f82680
  • tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els5_all.deb
    sha:534c50c9e65fa0780933dfdd383bfac2da1a92a1
  • tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els5_all.deb
    sha:27e3bed5a471944c00717a5bf5111630bb9d456f
  • tomcat9-user_9.0.31-1~deb10u12+tuxcare.els5_all.deb
    sha:e8971b06aad709739d776baa73d42a6146545535
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.