[ubuntu/questing-security] tomcat9 9.0.95-1ubuntu1.1 (Accepted)
Vyom Yadav
vyom.yadav at canonical.com
Wed Jun 10 05:47:16 UTC 2026
tomcat9 (9.0.95-1ubuntu1.1) questing-security; urgency=medium
* SECURITY UPDATE: denial of service via unbounded WebDAV request body
- debian/patches/CVE-2026-41284.patch: add BoundedByteArrayOutputStream
to limit LOCK and PROPFIND request body size
- CVE-2026-41284
* SECURITY UPDATE: HTTP/2 header field validation bypass
- debian/patches/CVE-2026-41293-pre.patch: add header validation
infrastructure for HTTP/2 field names and values
- debian/patches/CVE-2026-41293.patch: improve header field name and
value validation in HpackDecoder and HPackHuffman
- CVE-2026-41293
* SECURITY UPDATE: exposure of HTTP auth header to unexpected hosts
- debian/patches/CVE-2026-42498.patch: clear authentication headers
after use and fix digest auth method handling
- CVE-2026-42498
* SECURITY UPDATE: authorization bypass via multiple method constraints
- debian/patches/CVE-2026-43515.patch: check all matching
SecurityCollection entries in RealmBase
- CVE-2026-43515
* SECURITY UPDATE: NullPointerException in digest authentication with
invalid user
- debian/patches/CVE-2026-43512.patch: add null check for password
in RealmBase.getDigest()
- CVE-2026-43512
* SECURITY UPDATE: account lockout bypass via case-variant usernames
- debian/patches/CVE-2026-43513.patch: normalize username case in
LockOutRealm when caseSensitive is false
- CVE-2026-43513
Date: 2026-06-09 18:11:51.519447+00:00
Changed-By: Vyom Yadav <vyom.yadav at canonical.com>
https://launchpad.net/ubuntu/+source/tomcat9/9.0.95-1ubuntu1.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Questing-changes
mailing list