{"id":"CLSA-2026-1779968889","summary":"Fix of 7 CVEs","details":"   * SECURITY UPDATE: Authentication Bypass in digest authentication\n     - debian/patches/CVE-2026-43512.patch: reject digest authentication\n       attempts for unknown users in getDigest()\n     - CVE-2026-43512\n   * SECURITY UPDATE: Account lockout bypass in LockOutRealm via case\n     variation of user names\n     - debian/patches/CVE-2026-43513.patch: add a caseSensitive attribute\n       to LockOutRealm and treat user names case-insensitively by default\n     - CVE-2026-43513\n   * SECURITY UPDATE: Observable timing discrepancy in AJP secret comparison\n     - debian/patches/CVE-2026-43514.patch: add ConstantTime helper and\n       switch the AJP secret comparison to a constant time algorithm\n     - CVE-2026-43514\n   * SECURITY UPDATE: Improper authorisation when multiple method\n     constraints define an HTTP method for the same extension\n     - debian/patches/CVE-2026-43515.patch: evaluate findMethod() against\n       every matching SecurityCollection rather than only the last one\n     - CVE-2026-43515\n   * SECURITY UPDATE: Exposure of HTTP authorisation header to unexpected\n     hosts during WebSocket authentication\n     - debian/patches/CVE-2026-42498.patch: drop the cached Authorization\n       header from userProperties before following a WebSocket upgrade\n       redirect so it is not sent to the host named in Location\n     - CVE-2026-42498\n   * SECURITY UPDATE: HTTP/2 header values were not validated for control\n     characters and other illegal bytes\n     - debian/patches/CVE-2026-41293.patch: validate field names and values\n       in HpackDecoder and HPackHuffman using the new HttpParser\n       isFieldVChar / isFieldContent tables\n     - CVE-2026-41293\n   * SECURITY UPDATE: Allocation of resources without limits in WebDAV\n     LOCK and PROPFIND request bodies\n     - debian/patches/CVE-2026-41284.patch: read PROPFIND and LOCK bodies\n       through a new BoundedByteArrayOutputStream limited by the new\n       maxRequestBodySize init parameter (default 4096 bytes)\n     - CVE-2026-41284","modified":"2026-06-04T10:05:01.041214218Z","published":"2026-05-28T14:02:01Z","upstream":["CVE-2026-41284","CVE-2026-41293","CVE-2026-42498","CVE-2026-43512","CVE-2026-43513","CVE-2026-43514","CVE-2026-43515"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779968889.html"}],"affected":[{"package":{"name":"libtomcat9-embed-java","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libtomcat9-embed-java?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1~deb10u12+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779968889.json"}},{"package":{"name":"libtomcat9-java","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libtomcat9-java?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1~deb10u12+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779968889.json"}},{"package":{"name":"tomcat9","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/tomcat9?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1~deb10u12+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779968889.json"}},{"package":{"name":"tomcat9-admin","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/tomcat9-admin?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1~deb10u12+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779968889.json"}},{"package":{"name":"tomcat9-common","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/tomcat9-common?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1~deb10u12+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779968889.json"}},{"package":{"name":"tomcat9-docs","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/tomcat9-docs?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1~deb10u12+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779968889.json"}},{"package":{"name":"tomcat9-examples","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/tomcat9-examples?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1~deb10u12+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779968889.json"}},{"package":{"name":"tomcat9-user","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/tomcat9-user?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.31-1~deb10u12+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779968889.json"}}],"schema_version":"1.7.5"}