Release date:
2026-05-28 14:02:01 UTC
Description:
* SECURITY UPDATE: Authentication Bypass in digest authentication
- debian/patches/CVE-2026-43512.patch: reject digest authentication
attempts for unknown users in getDigest()
- CVE-2026-43512
* SECURITY UPDATE: Account lockout bypass in LockOutRealm via case
variation of user names
- debian/patches/CVE-2026-43513.patch: add a caseSensitive attribute
to LockOutRealm and treat user names case-insensitively by default
- CVE-2026-43513
* SECURITY UPDATE: Observable timing discrepancy in AJP secret comparison
- debian/patches/CVE-2026-43514.patch: add ConstantTime helper and
switch the AJP secret comparison to a constant time algorithm
- CVE-2026-43514
* SECURITY UPDATE: Improper authorisation when multiple method
constraints define an HTTP method for the same extension
- debian/patches/CVE-2026-43515.patch: evaluate findMethod() against
every matching SecurityCollection rather than only the last one
- CVE-2026-43515
* SECURITY UPDATE: Exposure of HTTP authorisation header to unexpected
hosts during WebSocket authentication
- debian/patches/CVE-2026-42498.patch: drop the cached Authorization
header from userProperties before following a WebSocket upgrade
redirect so it is not sent to the host named in Location
- CVE-2026-42498
* SECURITY UPDATE: HTTP/2 header values were not validated for control
characters and other illegal bytes
- debian/patches/CVE-2026-41293.patch: validate field names and values
in HpackDecoder and HPackHuffman using the new HttpParser
isFieldVChar / isFieldContent tables
- CVE-2026-41293
* SECURITY UPDATE: Allocation of resources without limits in WebDAV
LOCK and PROPFIND request bodies
- debian/patches/CVE-2026-41284.patch: read PROPFIND and LOCK bodies
through a new BoundedByteArrayOutputStream limited by the new
maxRequestBodySize init parameter (default 4096 bytes)
- CVE-2026-41284
Updated packages:
-
libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els5_all.deb
sha:2d969cfeb8f2d2e05570b2277745b4f528506ddf
-
libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els5_all.deb
sha:8921f592921fc6989ead896f320808351b82d94d
-
tomcat9_9.0.31-1~deb10u12+tuxcare.els5_all.deb
sha:17c9d875467153bd39659c057cd07fc2ec12e910
-
tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els5_all.deb
sha:64215f5453cf59ad05b471bf461e7acf2875daba
-
tomcat9-common_9.0.31-1~deb10u12+tuxcare.els5_all.deb
sha:6d9917abfeab96706638de832758695267f82680
-
tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els5_all.deb
sha:534c50c9e65fa0780933dfdd383bfac2da1a92a1
-
tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els5_all.deb
sha:27e3bed5a471944c00717a5bf5111630bb9d456f
-
tomcat9-user_9.0.31-1~deb10u12+tuxcare.els5_all.deb
sha:e8971b06aad709739d776baa73d42a6146545535
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.