SUSE-SU-2026:23711-1: important: Security update for tomcat10
SLE-SECURITY-UPDATES
null at suse.de
Wed Sep 16 16:40:45 UTC 2026
# Security update for tomcat10
Announcement ID: SUSE-SU-2026:23711-1
Release Date: 2026-09-08T15:47:18Z
Rating: important
References:
* bsc#1273150
* bsc#1276893
* bsc#1276894
* bsc#1276895
* bsc#1276896
* bsc#1276897
* bsc#1276898
* bsc#1276899
* bsc#1276900
* bsc#1276901
* bsc#1276902
Cross-References:
* CVE-2026-32990
* CVE-2026-65182
* CVE-2026-65183
* CVE-2026-65637
* CVE-2026-65905
* CVE-2026-65927
* CVE-2026-66299
* CVE-2026-66422
* CVE-2026-68525
* CVE-2026-68569
* CVE-2026-68763
* CVE-2026-73180
CVSS scores:
* CVE-2026-32990 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-65182 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-65637 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-65637 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-65637 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-65905 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-65905 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-65905 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-65927 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-65927 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-65927 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-66299 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-66299 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-66299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-66299 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-66422 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-66422 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-66422 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-68525 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-68525 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-68525 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-68569 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-68569 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-68569 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-68763 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-68763 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-68763 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-73180 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-73180 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-73180 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Products:
* SUSE Linux Enterprise Server 16.0
* SUSE Linux Enterprise Server for SAP applications 16.0
An update that solves 12 vulnerabilities can now be installed.
## Description:
This update for tomcat10 fixes the following issues:
* CVE-2026-65182: Bypass longest prefix security constraint (bsc#1276893).
* CVE-2026-65183: TOCTOU when setting specific permissions for Unix Domain
Sockets (bsc#1276894).
* CVE-2026-65637: HTTP/2 no-authority bypass of strict SNI validation - fix
incomplete (bsc#1276895).
* CVE-2026-65905: Limited replay attack possible with DIGEST authentication
(bsc#1276896).
* CVE-2026-65927: RewriteValve [N] restarts at the second rule and may bypass
access control (bsc#1276897).
* CVE-2026-66299: memory exhaustion via maliciously slow clients due to the
WebSocket chat example providing an unbounded buffer for undelivered
messages (bsc#1273150).
* CVE-2026-66422: Servlet role references can bypass declarative role
constraints (bsc#1276898).
* CVE-2026-68525: Redirect after FORM auth may bypass method specific
constraints (bsc#1276899).
* CVE-2026-68569: Principal lookup can fail open in some cases (bsc#1276900).
* CVE-2026-68763: DoS via allocation leak in HTTP/2 backlog tracking when a
stream is reset (bsc#1276901).
* CVE-2026-73180: Authenticated WebSocket session survives end of HTTP session
(bsc#1276902).
Changes for tomcat10:
* Update to Tomcat 10.1.59
* Catalina
* Fix: Ensure that a login-config conflict when merging web.xml fragments
triggers a deployment failure. (markt)
* Code: Remove unnecessary calls to String.intern() in the parsing of
configuration files. (markt)
* Fix: Extend sessionAttributeValueClassNameFilter to include filtering of
dynamic proxy interface classes. (markt)
* Fix: Attempt to use rollback when persisting user data to the
DataSourceUserDatabase fails and improve error reporting. (remm)
* Fix: 70143: Handle InvalidFileNameException when parsing parts to rethrow it
as an IllegalStateException as mandated by the Servlet specification. (remm)
* Fix: Add missing reason to the JsonErrorReportValve. (remm)
* Fix: evaluation of the N and C flags for rewrite rules. (remm)
* Fix: qsd flag should always discard the original query string when
rewriting. (remm)
* Fix: Add appropriate escaping for context path, current directory name and
parent directory name for directory listings produced by the default
servlet. Ensure XML escaping is used with XML output. (markt)
* Fix: When processing certificate subject names and issuer names within
RewriteValve rules, always use the RFC 2253 format name. (markt)
* Fix: the incorrect rejection of requests using digest authentication when
the client provided nonce count is at the upper boundary of the window
(markt).
* Update: Separate the Context role mapping from the Servlet specification
security-role-ref. (remm)
* Fix: Handle the case where the JNDIRealm is configured to perform role
searches with userRoleAttribute but the attribute is not available or not
configured for the current user. (markt)
* Fix: Improve handling of session attribute addition concurrent with session
expiration. An application will now either see a successful addition
followed by expiration or the addition will not succeed. It is no longer
possible for the session to expire and the addition to succeed. This is of
particular not for attributes that implement HttpSessionBindingListener.
(markt)
* Fix: Add a new attribute to the Context, urlPatternsProvidedInDecodedForm.
This attribute controls whether URLs and URL patterns provided in the
deployment descriptor (web.xml), annotations and/or their programmatic
equivalents are treated as being provided in URL-encoded form (i.e. using
%nn encoding) or in decoded form. The Servlet specification requires that
they are provided in decoded form. However, Tomcat has historically treated
them as if they are provided in encoded form. In Tomcat 12, they will always
be treated as if they are provided in decoded form. This setting enables
migration from encoded form to decoded form on an application by application
basis. This attribute will be removed in Tomcat 12 where it will effectively
be hard-coded to true. (markt)
* Fix: Ensure the security constraint with the longest matching path is
selected when more than one constraint matches the request path. (markt)
* Fix: If the request saved by FORM authentication uses a method other than
GET, ensure that the security constraints are re-assessed after the saved
request is restored and before it is processed. Custom Authenticator
implementations that extend FormAuthenticator and override doAuthenticate()
and/or restoreRequest() will require modification. (markt)
* Fix: Various improvements to the DataSourceRealm. A failure to connect to
the database or an exception during either user or role lookup will now
result in an authentication failure rather than a partially populated
Principal. For CLIENT-CERT and SPNEGO authentication, the user must exist in
the database for authentication to succeed. (markt)
* Fix: Improve the handling of AsyncContext.dispatch() when the Context
attribute dispatchersUseEncodedPaths is set to false since the application
has no control over the path used for the AsyncContext.dispatch(). Prior to
this fix, paths containing literal '?' characters were truncated. (markt)
* Fix: Ensure that capture groups from a RewriteCond always reflect the result
of the current request. (markt)
* Fix: async path building. (markt)
* Coyote
* Update: Add utility AutoCloseable URLConnection wrapper, and use it to
cleanup existing code patterns. (remm/markt)
* Fix: When processing an HTTP upgrade from HTTP/1.1 to HTTP/2, ensure that
all the HTTP/1.1 data has been processed before switching protocols. (markt)
* Fix: Require every HTTP/2 request to provide an authority (either an
:authority pseudo header or a Host header). (markt)
* Fix: Register the use of an HTTP/2 stream identifier earlier so that there
is no possibility of a re-used stream identifier being accepted, regardless
of how early in the HEADERS frame processing an error is detected. (markt)
* Add: new attributes (unixDomainSocketParentPermissions and
unixDomainSocketParentOwner) to the NIO connector to provide additional
control over the security of Unix Domain Sockets. Additional checks (enabled
by default) have also been added for the directory where the Unix Domain
Socket will be created.(markt)
* Fix: an allocation leak in the HTTP/2 backlog tracking when a stream is
reset. (markt)
* Fix: parsing of client certificates that specify more than one OCSP
responder for configurations that use OpenSSL-FFM. (markt)
* Jasper
* Fix: Ensure internal state is reset before re-using ELParser. (markt)
* WebSocket
* Add: a limit (defaults to 8KB) on the size of the HTTP response headers
accepted during a WebSocket HTTP upgrade. This is configured via the
org.apache.tomcat.websocket.MAX_HTTP_RESPONSE_HEADER_BYTES user property.
(markt)
* Fix: Improve URI template matching for WebSocket end points. Trailing
slashes are now significant both for template definitions and URIs
considered for potential matches to those URIs. Note that this means if a
URI template ends in a variable without a trailing slash, that variable
might be expanded to the empty string. (markt)
* Fix: Account for session ID changes when tracking WebSocket connections for
closure because they were created under an authenticated HTTP session that
has since ended. (markt)
* Web applications
* Fix: Documentation: Better sample httpd configuration for use with SSLValve
and add a note that the exact configuration required will depend on the
overall httpd configuration. (markt)
* Fix: Examples: Limit the buffering of messages in the WebSocket chat example
to prevent a malicious client triggering excessive memory usage that could
lead to a DoS. (markt)
* Fix: Documentation: Expand the description of the %S (session ID) access log
pattern token. (markt)
* Fix: Manager: Use reflection to load clustering classes in sessionsList.jsp
so the sessions list page renders correctly when clustering JARs are not
present. (csutherl)
* Other
* Update: Maven Resolver Ant Tasks to 1.6.1. (rjung)
* Update: Objenesis to 3.6. (markt)
* Update: JSign to 7.5. (markt)
* Update: Bouncy Castle to 1.85. (markt)
* Add: Improvements to French translations. (remm)
* Add: Improvements to Japanese translations provided by tak7iji. (markt)
* Cluster
* Add: Change the default encryptionAlgorithm for the EncryptInterceptor to
AES/GCM/NoPadding. This is a breaking change for the EncryptInterceptor.
(markt)
* Add: Expand the documentation for the EncryptInterceptor to be more explicit
regarding the security weaknesses of some supported algorithms. Also
explicitly state that the replay protection is only effective for non-
malleable algorithms. (markt)
* Add: Expand the Javadoc for the DNSMembershipProvider in particular
explaining its behaviour and providing configuration advice if control more
over cluster membership is required. (markt)
* jdbc-pool
* Fix: 70164: Correct the documentation for the testOnBorrow attribute. Pull
request #1033 provided by Kohei Tamura. (markt)
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP applications 16.0
zypper in -t patch SUSE-SLES-16.0-1641
* SUSE Linux Enterprise Server 16.0
zypper in -t patch SUSE-SLES-16.0-1641
## Package List:
* SUSE Linux Enterprise Server for SAP applications 16.0 (noarch)
* tomcat10-embed-10.1.59-160000.1.1
* tomcat10-admin-webapps-10.1.59-160000.1.1
* tomcat10-10.1.59-160000.1.1
* tomcat10-el-5_0-api-10.1.59-160000.1.1
* tomcat10-doc-10.1.59-160000.1.1
* tomcat10-jsvc-10.1.59-160000.1.1
* tomcat10-servlet-6_0-api-10.1.59-160000.1.1
* tomcat10-docs-webapp-10.1.59-160000.1.1
* tomcat10-jsp-3_1-api-10.1.59-160000.1.1
* tomcat10-lib-10.1.59-160000.1.1
* tomcat10-webapps-10.1.59-160000.1.1
* SUSE Linux Enterprise Server 16.0 (noarch)
* tomcat10-embed-10.1.59-160000.1.1
* tomcat10-admin-webapps-10.1.59-160000.1.1
* tomcat10-10.1.59-160000.1.1
* tomcat10-el-5_0-api-10.1.59-160000.1.1
* tomcat10-doc-10.1.59-160000.1.1
* tomcat10-jsvc-10.1.59-160000.1.1
* tomcat10-servlet-6_0-api-10.1.59-160000.1.1
* tomcat10-docs-webapp-10.1.59-160000.1.1
* tomcat10-jsp-3_1-api-10.1.59-160000.1.1
* tomcat10-lib-10.1.59-160000.1.1
* tomcat10-webapps-10.1.59-160000.1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-32990.html
* https://www.suse.com/security/cve/CVE-2026-65182.html
* https://www.suse.com/security/cve/CVE-2026-65183.html
* https://www.suse.com/security/cve/CVE-2026-65637.html
* https://www.suse.com/security/cve/CVE-2026-65905.html
* https://www.suse.com/security/cve/CVE-2026-65927.html
* https://www.suse.com/security/cve/CVE-2026-66299.html
* https://www.suse.com/security/cve/CVE-2026-66422.html
* https://www.suse.com/security/cve/CVE-2026-68525.html
* https://www.suse.com/security/cve/CVE-2026-68569.html
* https://www.suse.com/security/cve/CVE-2026-68763.html
* https://www.suse.com/security/cve/CVE-2026-73180.html
* https://bugzilla.suse.com/show_bug.cgi?id=1273150
* https://bugzilla.suse.com/show_bug.cgi?id=1276893
* https://bugzilla.suse.com/show_bug.cgi?id=1276894
* https://bugzilla.suse.com/show_bug.cgi?id=1276895
* https://bugzilla.suse.com/show_bug.cgi?id=1276896
* https://bugzilla.suse.com/show_bug.cgi?id=1276897
* https://bugzilla.suse.com/show_bug.cgi?id=1276898
* https://bugzilla.suse.com/show_bug.cgi?id=1276899
* https://bugzilla.suse.com/show_bug.cgi?id=1276900
* https://bugzilla.suse.com/show_bug.cgi?id=1276901
* https://bugzilla.suse.com/show_bug.cgi?id=1276902
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260916/1edb3c1b/attachment.htm>
More information about the sle-security-updates
mailing list