Advisories ยป MGASA-2026-0479

Updated tomcat package fixes security vulnerabilities

Publication date: 09 Oct 2026
Modification date: 09 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-73581 , CVE-2026-75973 , CVE-2026-76183 , CVE-2026-77756 , CVE-2026-77762 , CVE-2026-77791 , CVE-2026-78383 , CVE-2026-78437 , CVE-2026-79677 , CVE-2026-86248 , CVE-2026-86350 , CVE-2026-87022

Description

OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate
uses a keystore. (CVE-2026-73581)
Cross-context authentication mix-up with Jakarta Authentication
configured. (CVE-2026-75973)
Bypass of security constraints for WebSocket endpoints. (CVE-2026-76183)
Transfer-Encoding honored for HTTP/1.0 requests. (CVE-2026-77756)
Stale HPACK emitter injects trailers into recycled pooled Request.
(CVE-2026-77762)
DoS via busy wait during WebSocket close. (CVE-2026-77791)
AJP DoS via missing request body. (CVE-2026-78383)
HTTP/2 DoS via malformed request. (CVE-2026-78437)
WebSocket DoS due to lost asynchronous write timeout. (CVE-2026-79677)
Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail
with FFM even when soft-fail is disabled. (CVE-2026-86248)
Regression in fix for CVE-2026-41293 can trigger request header mix-up.
(CVE-2026-86350)
WebSocket message smuggling with per-message-deflate. (CVE-2026-87022)
                

References

SRPMS

10/core