Numerous CVEs of varying levels of severity have been issued for Tomcat.
Please upgrade to the latest version at your earliest convenience.
Begin forwarded message:
> From: Mark Thomas <markt@xxxxxxxxxx>
> Date: August 25, 2026 at 3:38:24 PM MDT
> To: Tomcat Users List <users@xxxxxxxxxxxxxxxxx>, announce@xxxxxxxxxxxxxxxxx,
> announce@xxxxxxxxxx, Tomcat Developers List <dev@xxxxxxxxxxxxxxxxx>
> Subject: [SECURITY] CVE-2026-65182 Apache Tomcat - Security constraint bypass
> Reply-To: announce@xxxxxxxxxxxxxxxxx
>
> CVE-2026-65182 Apache Tomcat - Security constraint bypass
>
> Severity: Important
>
> Vendor: The Apache Software Foundation
>
> Versions Affected:
> Apache Tomcat 11.0.0-M1 to 11.0.24
> Apache Tomcat 10.1.0-M1 to 10.1.57
> Apache Tomcat 9.0.0.M1 to 9.0.120
>
> Description:
> The security constraint processing enabled a security constraint bypass if a
> constraint for a longer path was specified before a more restrictive
> constraint for a shorter sub-path.
>
> Mitigation:
> Users of the affected versions should apply one of the following
> mitigations:
> - Remove the examples web application
> - Upgrade to Apache Tomcat 11.0.25
> - Upgrade to Apache Tomcat 10.1.59
> - Upgrade to Apache Tomcat 9.0.121
>
> Note: This issue was fixed in Apache Tomcat 10.1.58 but the release vote for
> the 10.1.58 release candidate did not pass. Therefore, although users must
> download 10.1.59 to obtain a version that includes a fix for this issue,
> version 10.1.58 is not included in the list of affected versions.
>
> Credit:
> This issue was identified by:
> - 4ra1n, pyn3rd and unam4
>
> History:
> 2026-08-25 Original advisory
>
> References:
> [1] https://tomcat.apache.org/security-11.html
> [2] https://tomcat.apache.org/security-10.html
> [3] https://tomcat.apache.org/security-9.html
>