[thredds] Fwd: [SECURITY] CVE-2026-65182 Apache Tomcat - Security constraint bypass

  • To: thredds@xxxxxxxxxxxxxxxx
  • Subject: [thredds] Fwd: [SECURITY] CVE-2026-65182 Apache Tomcat - Security constraint bypass
  • From: Jennifer Oxelson Ganter <oxelson@xxxxxxxx>
  • Date: Wed, 26 Aug 2026 07:49:32 -0600
Numerous CVEs of varying levels of severity have been issued for Tomcat.  
Please upgrade to the latest version at your earliest convenience. 


Begin forwarded message:

> From: Mark Thomas <markt@xxxxxxxxxx>
> Date: August 25, 2026 at 3:38:24 PM MDT
> To: Tomcat Users List <users@xxxxxxxxxxxxxxxxx>, announce@xxxxxxxxxxxxxxxxx, 
> announce@xxxxxxxxxx, Tomcat Developers List <dev@xxxxxxxxxxxxxxxxx>
> Subject: [SECURITY] CVE-2026-65182 Apache Tomcat - Security constraint bypass
> Reply-To: announce@xxxxxxxxxxxxxxxxx
> 
> CVE-2026-65182 Apache Tomcat - Security constraint bypass
> 
> Severity: Important
> 
> Vendor: The Apache Software Foundation
> 
> Versions Affected:
> Apache Tomcat 11.0.0-M1 to 11.0.24
> Apache Tomcat 10.1.0-M1 to 10.1.57
> Apache Tomcat 9.0.0.M1 to 9.0.120
> 
> Description:
> The security constraint processing enabled a security constraint bypass if a 
> constraint for a longer path was specified before a more restrictive 
> constraint for a shorter sub-path.
> 
> Mitigation:
> Users of the affected versions should apply one of the following
> mitigations:
> - Remove the examples web application
> - Upgrade to Apache Tomcat 11.0.25
> - Upgrade to Apache Tomcat 10.1.59
> - Upgrade to Apache Tomcat 9.0.121
> 
> Note: This issue was fixed in Apache Tomcat 10.1.58 but the release vote for 
> the 10.1.58 release candidate did not pass. Therefore, although users must 
> download 10.1.59 to obtain a version that includes a fix for this issue, 
> version 10.1.58 is not included in the list of affected versions.
> 
> Credit:
> This issue was identified by:
> - 4ra1n, pyn3rd and unam4
> 
> History:
> 2026-08-25 Original advisory
> 
> References:
> [1] https://tomcat.apache.org/security-11.html
> [2] https://tomcat.apache.org/security-10.html
> [3] https://tomcat.apache.org/security-9.html
>