<div class="container">
    <h1>Security update for tomcat11</h1>

    <table class="table table-striped table-bordered">
        <tbody>
        <tr>
            <th>Announcement ID:</th>
            <td>SUSE-SU-2026:23691-1</td>
        </tr>
        <tr>
            <th>Release Date:</th>
            <td>2026-09-08T15:49:16Z</td>
        </tr>
        
        <tr>
            <th>Rating:</th>
            <td>important</td>
        </tr>
        <tr>
            <th>References:</th>
            <td>
                <ul>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1273150">bsc#1273150</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276893">bsc#1276893</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276894">bsc#1276894</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276895">bsc#1276895</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276896">bsc#1276896</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276897">bsc#1276897</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276898">bsc#1276898</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276899">bsc#1276899</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276900">bsc#1276900</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276901">bsc#1276901</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276902">bsc#1276902</a>
                        </li>
                    
                    
                </ul>
            </td>
        </tr>
        
            <tr>
                <th>
                    Cross-References:
                </th>
                <td>
                    <ul>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-32990.html">CVE-2026-32990</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-65182.html">CVE-2026-65182</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-65183.html">CVE-2026-65183</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-65637.html">CVE-2026-65637</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-65905.html">CVE-2026-65905</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-65927.html">CVE-2026-65927</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-66299.html">CVE-2026-66299</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-66422.html">CVE-2026-66422</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-68525.html">CVE-2026-68525</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-68569.html">CVE-2026-68569</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-68763.html">CVE-2026-68763</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-73180.html">CVE-2026-73180</a>
                        </li>
                    
                    </ul>
                </td>
            </tr>
            <tr>
                <th>CVSS scores:</th>
                <td>
                    <ul class="list-group">
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-32990</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65182</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.7</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65182</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65182</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65183</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65183</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65637</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.9</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65637</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65637</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.8</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65905</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.9</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65905</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65905</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.8</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65927</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.9</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65927</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-65927</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-66299</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.7</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-66299</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-66299</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-66299</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-66422</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.9</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-66422</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-66422</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-68525</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.9</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-68525</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-68525</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-68569</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.9</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-68569</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-68569</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-68763</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.7</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-68763</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-68763</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-73180</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.9</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-73180</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-73180</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.8</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                    </ul>
                </td>
            </tr>
        
        <tr>
            <th>Affected Products:</th>
            <td>
                <ul class="list-group">
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 16.0</li>
                    
                </ul>
            </td>
        </tr>
        </tbody>
    </table>

    <p>An update that solves 12 vulnerabilities can now be installed.</p>

    


    
        <h2>Description:</h2>
    
    <p>This update for tomcat11 fixes the following issues:</p>
<ul>
<li>CVE-2026-65182: Bypass longest prefix security constraint (bsc#1276893).</li>
<li>CVE-2026-65183: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894).</li>
<li>CVE-2026-65637: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895).</li>
<li>CVE-2026-65905: Limited replay attack possible with DIGEST authentication (bsc#1276896).</li>
<li>CVE-2026-65927: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897).</li>
<li>CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an
  unbounded buffer for undelivered messages (bsc#1273150).</li>
<li>CVE-2026-66422: Servlet role references can bypass declarative role constraints (bsc#1276898).</li>
<li>CVE-2026-68525: Redirect after FORM auth may bypass method specific constraints (bsc#1276899).</li>
<li>CVE-2026-68569: Principal lookup can fail open in some cases (bsc#1276900).</li>
<li>CVE-2026-68763: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset (bsc#1276901).</li>
<li>CVE-2026-73180: Authenticated WebSocket session survives end of HTTP session (bsc#1276902).</li>
</ul>
<p>Changes for tomcat11:</p>
<ul>
<li>Update to Tomcat 11.0.25</li>
<li>Catalina</li>
<li>Fix: Ensure that a login-config conflict when merging web.xml fragments
 triggers a deployment failure. (markt)</li>
<li>Code: Remove unnecessary calls to String.intern() in the parsing of
 configuration files. (markt)</li>
<li>Fix: Extend sessionAttributeValueClassNameFilter to include filtering of
 dynamic proxy interface classes. (markt)</li>
<li>Fix: Attempt to use rollback when persisting user data to the
 DataSourceUserDatabase fails and improve error reporting. (remm)</li>
<li>Fix: 70143: Handle InvalidFileNameException when parsing parts to
 rethrow it as an IllegalStateException as mandated by the Servlet
 specification. (remm)</li>
<li>Fix: Add missing reason to the JsonErrorReportValve. (remm)</li>
<li>Fix: evaluation of the N and C flags for rewrite rules. (remm)</li>
<li>Fix: qsd flag should always discard the original query string when
 rewriting. (remm)</li>
<li>Fix: Add appropriate escaping for context path, current directory name
 and parent directory name for directory listings produced by the default
 servlet. Ensure XML escaping is used with XML output. (markt)</li>
<li>Fix: When processing certificate subject names and issuer names within
 RewriteValve rules, always use the RFC 2253 format name. (markt)</li>
<li>Fix: the incorrect rejection of requests using digest authentication
 when the client provided nonce count is at the upper boundary of the
 window (markt).</li>
<li>Update: Separate the Context role mapping from the Servlet specification
 security-role-ref. (remm)</li>
<li>Fix: Handle the case where the JNDIRealm is configured to perform role
 searches with userRoleAttribute but the attribute is not available or
 not configured for the current user. (markt)</li>
<li>Fix: Improve handling of session attribute addition concurrent with
 session expiration. An application will now either see a successful
 addition followed by expiration or the addition will not succeed. It is
 no longer possible for the session to expire and the addition to
 succeed. This is of particular not for attributes that implement
 HttpSessionBindingListener. (markt)</li>
<li>Fix: Add a new attribute to the Context,
 urlPatternsProvidedInDecodedForm. This attribute controls whether URLs
 and URL patterns provided in the deployment descriptor (web.xml),
 annotations and/or their programmatic equivalents are treated as being
 provided in URL-encoded form (i.e. using %nn encoding) or in decoded
 form. The Servlet specification requires that they are provided in
 decoded form. However, Tomcat has historically treated them as if they
 are provided in encoded form. In Tomcat 12, they will always be treated
 as if they are provided in decoded form. This setting enables migration
 from encoded form to decoded form on an application by application
 basis. This attribute will be removed in Tomcat 12 where it will
 effectively be hard-coded to true. (markt)</li>
<li>Fix: Ensure the security constraint with the longest matching path is
 selected when more than one constraint matches the request path. (markt)</li>
<li>Fix: If the request saved by FORM authentication uses a method other
 than GET, ensure that the security constraints are re-assessed after the
 saved request is restored and before it is processed. Custom
 Authenticator implementations that extend FormAuthenticator and override
 doAuthenticate() and/or restoreRequest() will require modification.
 (markt)</li>
<li>Fix: Various improvements to the DataSourceRealm. A failure to connect
 to the database or an exception during either user or role lookup will
 now result in an authentication failure rather than a partially
 populated Principal. For CLIENT-CERT and SPNEGO authentication, the user
 must exist in the database for authentication to succeed. (markt)</li>
<li>Coyote</li>
<li>Update: Add utility AutoCloseable URLConnection wrapper, and use it to
 cleanup existing code patterns. (remm/markt)</li>
<li>Fix: When processing an HTTP upgrade from HTTP/1.1 to HTTP/2, ensure
 that all the HTTP/1.1 data has been processed before switching
 protocols. (markt)</li>
<li>Fix: Require every HTTP/2 request to provide an authority (either an
 :authority pseudo header or a Host header). (markt)</li>
<li>Fix: Register the use of an HTTP/2 stream identifier earlier so that
 there is no possibility of a re-used stream identifier being accepted,
 regardless of how early in the HEADERS frame processing an error is
 detected. (markt)</li>
<li>Add: new attributes (unixDomainSocketParentPermissions and
 unixDomainSocketParentOwner) to the NIO connector to provide additional
 control over the security of Unix Domain Sockets. Additional checks
 (enabled by default) have also been added for the directory where the
 Unix Domain Socket will be created.(markt)</li>
<li>Fix: an allocation leak in the HTTP/2 backlog tracking when a stream is
 reset. (markt)</li>
<li>Jasper</li>
<li>Fix: Ensure internal state is reset before re-using ELParser. (markt)</li>
<li>WebSocket</li>
<li>Add: a limit (defaults to 8KB) on the size of the HTTP response headers
 accepted during a WebSocket HTTP upgrade. This is configured via the
 org.apache.tomcat.websocket.MAX_HTTP_RESPONSE_HEADER_BYTES user
 property. (markt)</li>
<li>Fix: Improve URI template matching for WebSocket end points. Trailing
 slashes are now significant both for template definitions and URIs
 considered for potential matches to those URIs. Note that this means if
 a URI template ends in a variable without a trailing slash, that
 variable might be expanded to the empty string. (markt)</li>
<li>Fix: Account for session ID changes when tracking WebSocket connections
 for closure because they were created under an authenticated HTTP
 session that has since ended. (markt)</li>
<li>Web applications</li>
<li>Fix: 70160: Correct various references to the Servlet specification to
 use version 6.1. (markt)</li>
<li>Fix: Documentation: Better sample httpd configuration for use with
 SSLValve and add a note that the exact configuration required will
 depend on the overall httpd configuration. (markt)</li>
<li>Fix: Examples: Limit the buffering of messages in the WebSocket chat
 example to prevent a malicious client triggering excessive memory usage
 that could lead to a DoS. (markt)</li>
<li>Fix: Documentation: Expand the description of the %S (session ID) access
 log pattern token. (markt)</li>
<li>Fix: Manager: Use reflection to load clustering classes in
 sessionsList.jsp so the sessions list page renders correctly when
 clustering JARs are not present. (csutherl)</li>
<li>Other</li>
<li>Update: Maven Resolver Ant Tasks to 1.6.1. (rjung)</li>
<li>Update: Objenesis to 3.6. (markt)</li>
<li>Update: JSign to 7.5. (markt)</li>
<li>Update: Bouncy Castle to 1.85. (markt)</li>
<li>Add: Improvements to French translations. (remm)</li>
<li>Add: Improvements to Japanese translations provided by tak7iji. (markt)</li>
<li>Cluster</li>
<li>Add: Change the default encryptionAlgorithm for the EncryptInterceptor
 to AES/GCM/NoPadding. This is a breaking change for the
 EncryptInterceptor. (markt)</li>
<li>Add: Expand the documentation for the EncryptInterceptor to be more
 explicit regarding the security weaknesses of some supported algorithms.
 Also explicitly state that the replay protection is only effective for
 non-malleable algorithms. (markt)</li>
<li>Add: Expand the Javadoc for the DNSMembershipProvider in particular
 explaining its behaviour and providing configuration advice if control
 more over cluster membership is required. (markt)</li>
<li>jdbc-pool</li>
<li>Fix: 70164: Correct the documentation for the testOnBorrow attribute.
 Pull request #1033 provided by Kohei Tamura. (markt)</li>
</ul>



    

    <h2>Patch Instructions:</h2>
    <p>
        To install this SUSE  update use the SUSE recommended
        installation methods like YaST online_update or "zypper patch".<br/>

        Alternatively you can run the command listed for your product:
    </p>
    <ul class="list-group">
        
            <li class="list-group-item">
                SUSE Linux Enterprise Server 16.0
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLES-16.0-1642</code>
                    
                    
                
            </li>
        
    </ul>

    <h2>Package List:</h2>
    <ul>
        
            
                <li>
                    SUSE Linux Enterprise Server 16.0 (noarch)
                    <ul>
                        
                            <li>tomcat11-el-6_0-api-11.0.25-160000.1.1</li>
                        
                            <li>tomcat11-embed-11.0.25-160000.1.1</li>
                        
                            <li>tomcat11-jsvc-11.0.25-160000.1.1</li>
                        
                            <li>tomcat11-docs-webapp-11.0.25-160000.1.1</li>
                        
                            <li>tomcat11-servlet-6_1-api-11.0.25-160000.1.1</li>
                        
                            <li>tomcat11-webapps-11.0.25-160000.1.1</li>
                        
                            <li>tomcat11-11.0.25-160000.1.1</li>
                        
                            <li>tomcat11-admin-webapps-11.0.25-160000.1.1</li>
                        
                            <li>tomcat11-lib-11.0.25-160000.1.1</li>
                        
                            <li>tomcat11-jsp-4_0-api-11.0.25-160000.1.1</li>
                        
                            <li>tomcat11-doc-11.0.25-160000.1.1</li>
                        
                    </ul>
                </li>
            
        
    </ul>

    
        <h2>References:</h2>
        <ul>
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-32990.html">https://www.suse.com/security/cve/CVE-2026-32990.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-65182.html">https://www.suse.com/security/cve/CVE-2026-65182.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-65183.html">https://www.suse.com/security/cve/CVE-2026-65183.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-65637.html">https://www.suse.com/security/cve/CVE-2026-65637.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-65905.html">https://www.suse.com/security/cve/CVE-2026-65905.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-65927.html">https://www.suse.com/security/cve/CVE-2026-65927.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-66299.html">https://www.suse.com/security/cve/CVE-2026-66299.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-66422.html">https://www.suse.com/security/cve/CVE-2026-66422.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-68525.html">https://www.suse.com/security/cve/CVE-2026-68525.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-68569.html">https://www.suse.com/security/cve/CVE-2026-68569.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-68763.html">https://www.suse.com/security/cve/CVE-2026-68763.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-73180.html">https://www.suse.com/security/cve/CVE-2026-73180.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1273150">https://bugzilla.suse.com/show_bug.cgi?id=1273150</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276893">https://bugzilla.suse.com/show_bug.cgi?id=1276893</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276894">https://bugzilla.suse.com/show_bug.cgi?id=1276894</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276895">https://bugzilla.suse.com/show_bug.cgi?id=1276895</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276896">https://bugzilla.suse.com/show_bug.cgi?id=1276896</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276897">https://bugzilla.suse.com/show_bug.cgi?id=1276897</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276898">https://bugzilla.suse.com/show_bug.cgi?id=1276898</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276899">https://bugzilla.suse.com/show_bug.cgi?id=1276899</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276900">https://bugzilla.suse.com/show_bug.cgi?id=1276900</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276901">https://bugzilla.suse.com/show_bug.cgi?id=1276901</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1276902">https://bugzilla.suse.com/show_bug.cgi?id=1276902</a>
                    </li>
                
            
        </ul>
    
</div>