{"id":"ROOT-APP-MAVEN-CVE-2026-25854","summary":"CVE-2026-25854 in io.root.org.apache.tomcat.embed:tomcat-embed-core - Patched by Root","details":"Root has patched CVE-2026-25854 in the io.root.org.apache.tomcat.embed:tomcat-embed-core package for Root:Maven. Multiple fixed versions available.","modified":"2026-05-22T13:30:04.590042704Z","published":"2026-05-22T06:36:01Z","upstream":["CVE-2026-25854"],"database_specific":{"source":"Root","distro_version":"","severity":"MEDIUM","distro":"maven"},"affected":[{"package":{"name":"io.root.org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Root:Maven"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.1.39-root.io.8"},{"fixed":"10.1.39-root.io.9"},{"fixed":"10.1.39-root.io.10"},{"fixed":"10.1.39-root.io.11"},{"fixed":"10.1.39-root.io.12"},{"fixed":"10.1.34-root.io.1"},{"fixed":"10.1.34-root.io.2"},{"fixed":"10.1.39-root.io.13"},{"fixed":"10.1.39-root.io.14"}]}],"database_specific":{"all_fixed_versions":["10.1.39-root.io.8","10.1.39-root.io.9","10.1.39-root.io.10","10.1.39-root.io.11","10.1.39-root.io.12","10.1.34-root.io.1","10.1.34-root.io.2","10.1.39-root.io.13","10.1.39-root.io.14"],"upstream_version":"10.1.39","total_fixed_versions":9,"root_patched":true,"source":"https://api.root.io/external/osv/ROOT-APP-MAVEN-CVE-2026-25854.json","root_patch_version":"root.io.14"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}