Tomcat 10.1.59: CVE-2026-41293 CVE-2026-43512 CVE-2026-43515 CVE-2026-65182 CVE-2026-65905 CVE-2026-68525 CVE-2026-24734 CVE-2026-24880 CVE-2026-34483 CVE-2026-34487 CVE-2026-41284 CVE-2026-42498 CVE-2026-43513 CVE-2025-66614 CVE-2026-25854 CVE-2026-43514 - #1150
Merged
Conversation
Bumps org.apache.tomcat.embed:tomcat-embed-core from 10.1.48 to 10.1.59. --- updated-dependencies: - dependency-name: org.apache.tomcat.embed:tomcat-embed-core dependency-version: 10.1.59 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
vharseko
approved these changes
Sep 30, 2026
vharseko
deleted the
dependabot/maven/openam-federation/openam-idpdiscovery/org.apache.tomcat.embed-tomcat-embed-core-10.1.59
branch
September 30, 2026 16:03
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
openam-federation/openam-idpdiscoverypinsorg.apache.tomcat.embed:tomcat-embed-core10.1.48. It came in with #1146 (#1145):CookieUtilsTestruns the preferred-IdP cookie through Tomcat'sRfc6265CookieProcessorto check that the header OpenAM writes is one the container accepts.10.1.48 is affected by 16 advisories, all open as Dependabot alerts on this
pom.xml, and every one of them is fixed in 10.1.58 or earlier:JsonAccessLogValveLOCKandPROPFINDhandlingLockOutRealmtreats user names as case-sensitiveThe dependency has
testscope: it is on the test classpath of this one module only and does not ship in any OpenAM artifact, and the test uses only the cookie parser and generator, none of the affected components. So the build is not exposed; the bump clears the alerts and keeps the test on a current Tomcat.Change
openam-federation/openam-idpdiscovery/pom.xml:tomcat-embed-core10.1.48 → 10.1.59 (testscope). No code changes.Testing
CI (
build-maven) runsCookieUtilsTestagainst 10.1.59.