openSUSE-SU-2026:21487-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21487-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21487-1
Upstream
CVE (2)
Related
Published
2026-07-30T10:41:32Z
Modified
2026-08-03T02:10:48Z
Summary
Security update for tomcat10
Details

This update for tomcat10 fixes the following issues:

Update to Tomcat 10.1.57.

Security issues fixed:

  • CVE-2026-59083: incorrect URL decoding in RewriteValve may allow security control bypass (bsc#1271397).
  • CVE-2026-59084: EncryptInterceptor requirements are not clearly documented (bsc#1271398).

Other updates and bugfixes:

  • Tomcat 10.1.57:
    • Catalina
      • Fix: Avoid a race condition with concurrent lookups for a singleton JNDI resource. (markt)
      • Fix: Improve the performance of range validation for the default servlet. (markt)
      • Fix: Avoid NPE in RewriteValve. (markt)
      • Fix: 70127: Fix use of Bootstrap through reflection by restoring the public constructor. Use through scripts was not affected. (remm)
      • Fix: Restore ability to extend many element classes from AbstractAccessLogValve. (remm)
      • Fix: Align DIGEST authentication with RFC 7616 and require clients to provide a valid qop parameter. (markt)
      • Fix: Use Files API to create temporary docBase when antiLockingDocBase is enabled. (markt)
      • Fix: Improve validation of configuration when DataSourceRealm starts. (remm)
      • Fix: JAASRealm should do a logout if login does not fail outright but does not produce a Principal. (remm)
      • Fix: Various edge cases for SSI substitutions, quoting and escaping.
      • Fix: unintentional conversion of literal + to a space during rule processing in the RewriteValve. (markt)
    • Coyote
      • Fix: Avoid a potential JVM crash if a suitable version of Tomcat Native is not available when the connector is explicitly configured to use Tomcat Native with OpenSSL for TLS. (markt)
    • Jasper
      • Fix: 70120: The fix for 69399 (itself a fix for a regression in the fix for 69333) was incomplete and tags that threw exceptions in doStartTag() and doEndTag() were incorrectly re-used. This fix prevents tags from being re-used if such an exception occurs. (markt)
      • Fix: 70135: Fix security classload regression. (remm)
      • Add: support for specifying Java 28 (with the value 28) as the compiler source and/or compiler target for JSP compilation. If used with an Eclipse JDT compiler version that does not support these values, a warning will be logged and the default will be used. (markt)
    • WebSocket
      • Fix: 70126: Fix WebSocket extension permessage-deflate so that it does not drop bytes if a compressed message inflates to more than the available buffer. Fix written by GPT-5.5. Test case written by Hironori Ichimiya. (markt)
      • Fix: Optimise WebSocket client processing of server responses during WebSocket HTTP upgrade process. (markt)
    • Other
      • Update: Byte Buddy to 1.18.9. (markt)
      • Update: UnboundID to 7.0.5. (markt)
      • Update: JaCoCo to 0.8.15. (markt)
      • Update: BND to 7.3.0. (markt)
      • Add: Improvements to French translations. (remm)
      • Add: Improvements to Japanese translations provided by tak7iji. (markt)
References

Affected packages

openSUSE:Leap 16.0 / tomcat10

Package

Name
tomcat10
Purl
pkg:rpm/opensuse/tomcat10&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.1.57-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "tomcat10": "10.1.57-160000.1.1",
            "tomcat10-admin-webapps": "10.1.57-160000.1.1",
            "tomcat10-doc": "10.1.57-160000.1.1",
            "tomcat10-docs-webapp": "10.1.57-160000.1.1",
            "tomcat10-el-5_0-api": "10.1.57-160000.1.1",
            "tomcat10-embed": "10.1.57-160000.1.1",
            "tomcat10-jsp-3_1-api": "10.1.57-160000.1.1",
            "tomcat10-jsvc": "10.1.57-160000.1.1",
            "tomcat10-lib": "10.1.57-160000.1.1",
            "tomcat10-servlet-6_0-api": "10.1.57-160000.1.1",
            "tomcat10-webapps": "10.1.57-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21487-1.json"