Updated tomcat packages fix security vulnerabilities
Publication date: 05 Aug 2026Modification date: 05 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50229 , CVE-2026-53404 , CVE-2026-53434 , CVE-2026-55276 , CVE-2026-55955 , CVE-2026-55956 , CVE-2026-55957
Description
The updated packages fix security vulnerabilities:
XSS in number guess example. (CVE-2026-50229)
Bad ornext processing in RewriteValve. (CVE-2026-53404)
Invalid CRL configuration doesn't trigger failure for FFM Connector.
(CVE-2026-53434)
Logged effective web.xml is incomplete. (CVE-2026-55276)
EncryptInterceptor not protected against replay attacks.
(CVE-2026-55955)
Security constraints for default servlet ignored method.
(CVE-2026-55956)
Authentication bypass with JNDIRealm and GSSAPI authenticated bind.
(CVE-2026-55957)
References
- https://bugs.mageia.org/show_bug.cgi?id=35783
- https://www.openwall.com/lists/oss-security/2026/06/29/20
- https://www.openwall.com/lists/oss-security/2026/06/29/21
- https://www.openwall.com/lists/oss-security/2026/06/29/22
- https://www.openwall.com/lists/oss-security/2026/06/29/23
- https://www.openwall.com/lists/oss-security/2026/06/29/24
- https://www.openwall.com/lists/oss-security/2026/06/29/25
- https://www.openwall.com/lists/oss-security/2026/06/29/26
- https://www.cve.org/CVERecord?id=CVE-2026-50229
- https://www.cve.org/CVERecord?id=CVE-2026-53404
- https://www.cve.org/CVERecord?id=CVE-2026-53434
- https://www.cve.org/CVERecord?id=CVE-2026-55276
- https://www.cve.org/CVERecord?id=CVE-2026-55955
- https://www.cve.org/CVERecord?id=CVE-2026-55956
- https://www.cve.org/CVERecord?id=CVE-2026-55957
SRPMS
10/core
- tomcat-9.0.119-1.mga10
9/core
- tomcat-9.0.119-1.mga9