Skip to content

Tomcat 10.1.59: CVE-2026-41293 CVE-2026-43512 CVE-2026-43515 CVE-2026-65182 CVE-2026-65905 CVE-2026-68525 CVE-2026-24734 CVE-2026-24880 CVE-2026-34483 CVE-2026-34487 CVE-2026-41284 CVE-2026-42498 CVE-2026-43513 CVE-2025-66614 CVE-2026-25854 CVE-2026-43514 - #1150

Merged
vharseko merged 1 commit into
masterfrom
dependabot/maven/openam-federation/openam-idpdiscovery/org.apache.tomcat.embed-tomcat-embed-core-10.1.59
Sep 30, 2026

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Problem

openam-federation/openam-idpdiscovery pins org.apache.tomcat.embed:tomcat-embed-core 10.1.48. It came in with #1146 (#1145): CookieUtilsTest runs the preferred-IdP cookie through Tomcat's Rfc6265CookieProcessor to check that the header OpenAM writes is one the container accepts.

10.1.48 is affected by 16 advisories, all open as Dependabot alerts on this pom.xml, and every one of them is fixed in 10.1.58 or earlier:

CVE Advisory Severity Fixed in Issue
CVE-2026-41293 GHSA-r29c-68gh-xp6x critical 10.1.55 HTTP/2 request headers not validated
CVE-2026-43512 GHSA-h6fc-48rj-7qqh critical 10.1.55 DIGEST authenticator authenticates any unknown user
CVE-2026-43515 GHSA-5m62-pw8w-7w9f critical 10.1.55 Security constraints not correctly applied
CVE-2026-65182 GHSA-gcx9-497g-6cp6 critical 10.1.58 Improper access control, incorrect authorization
CVE-2026-65905 GHSA-9xv2-5v5q-p794 critical 10.1.58 DIGEST authenticator bypass by capture-replay
CVE-2026-68525 GHSA-h3x4-894j-xpx5 critical 10.1.58 Incorrect authorization in FORM authentication
CVE-2026-24734 GHSA-mgp5-rv84-w37q high 10.1.52 Improper input validation
CVE-2026-24880 GHSA-563x-q5rq-57qp high 10.1.52 HTTP request/response smuggling
CVE-2026-34483 GHSA-rv64-5gf8-9qq8 high 10.1.54 Improper output escaping in JsonAccessLogValve
CVE-2026-34487 GHSA-x4m4-345f-5h5g high 10.1.54 Sensitive information written to the log
CVE-2026-41284 GHSA-gx5v-xp9w-j4cg high 10.1.55 Unbounded read in WebDAV LOCK and PROPFIND handling
CVE-2026-42498 GHSA-fv25-8xcx-gqjc high 10.1.55 WebSocket authentication header exposure
CVE-2026-43513 GHSA-5mp6-jrq3-r938 high 10.1.55 LockOutRealm treats user names as case-sensitive
CVE-2025-66614 GHSA-fpj8-gq4v-p354 medium 10.1.50 Client certificate verification bypass
CVE-2026-25854 GHSA-9m3c-qcxr-9x87 medium 10.1.53 Open redirect
CVE-2026-43514 GHSA-9m89-8frq-c98c low 10.1.55 AJP secret compared in non-constant time

The dependency has test scope: it is on the test classpath of this one module only and does not ship in any OpenAM artifact, and the test uses only the cookie parser and generator, none of the affected components. So the build is not exposed; the bump clears the alerts and keeps the test on a current Tomcat.

Change

openam-federation/openam-idpdiscovery/pom.xml: tomcat-embed-core 10.1.48 → 10.1.59 (test scope). No code changes.

Testing

CI (build-maven) runs CookieUtilsTest against 10.1.59.

Bumps org.apache.tomcat.embed:tomcat-embed-core from 10.1.48 to 10.1.59.

---
updated-dependencies:
- dependency-name: org.apache.tomcat.embed:tomcat-embed-core
  dependency-version: 10.1.59
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 30, 2026
@vharseko vharseko changed the title Bump org.apache.tomcat.embed:tomcat-embed-core from 10.1.48 to 10.1.59 in /openam-federation/openam-idpdiscovery Tomcat 10.1.59: CVE-2026-41293 CVE-2026-43512 CVE-2026-43515 CVE-2026-65182 CVE-2026-65905 CVE-2026-68525 CVE-2026-24734 CVE-2026-24880 CVE-2026-34483 CVE-2026-34487 CVE-2026-41284 CVE-2026-42498 CVE-2026-43513 CVE-2025-66614 CVE-2026-25854 CVE-2026-43514 Sep 30, 2026
@vharseko
vharseko merged commit 2771241 into master Sep 30, 2026
16 checks passed
@vharseko
vharseko deleted the dependabot/maven/openam-federation/openam-idpdiscovery/org.apache.tomcat.embed-tomcat-embed-core-10.1.59 branch September 30, 2026 16:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant