{"id":"MGASA-2026-0323","summary":"Updated tomcat packages fix security vulnerabilities","details":"The updated packages fix security vulnerabilities:\nXSS in number guess example. (CVE-2026-50229)\nBad ornext processing in RewriteValve. (CVE-2026-53404)\nInvalid CRL configuration doesn't trigger failure for FFM Connector.\n(CVE-2026-53434)\nLogged effective web.xml is incomplete. (CVE-2026-55276)\nEncryptInterceptor not protected against replay attacks.\n(CVE-2026-55955)\nSecurity constraints for default servlet ignored method.\n(CVE-2026-55956)\nAuthentication bypass with JNDIRealm and GSSAPI authenticated bind.\n(CVE-2026-55957)\n","modified":"2026-08-05T17:36:29.076495311Z","published":"2026-08-05T17:22:07Z","upstream":["CVE-2026-50229","CVE-2026-53404","CVE-2026-53434","CVE-2026-55276","CVE-2026-55955","CVE-2026-55956","CVE-2026-55957"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0323.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35783"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/06/29/20"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/06/29/21"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/06/29/22"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/06/29/23"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/06/29/24"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/06/29/25"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/06/29/26"}],"affected":[{"package":{"name":"tomcat","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/tomcat?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.119-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0323.json"}},{"package":{"name":"tomcat","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/tomcat?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.119-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0323.json"}}],"schema_version":"1.8.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}