Numerous CVEs of varying levels of severity have been issued for Tomcat. Please upgrade to the latest version at your earliest convenience.
Begin forwarded message:
CVE-2026-65182 Apache Tomcat - Security constraint bypassSeverity: ImportantVendor: The Apache Software FoundationVersions Affected:Apache Tomcat 11.0.0-M1 to 11.0.24Apache Tomcat 10.1.0-M1 to 10.1.57Apache Tomcat 9.0.0.M1 to 9.0.120Description:The security constraint processing enabled a security constraint bypass if a constraint for a longer path was specified before a more restrictive constraint for a shorter sub-path.Mitigation:Users of the affected versions should apply one of the followingmitigations:- Remove the examples web application- Upgrade to Apache Tomcat 11.0.25- Upgrade to Apache Tomcat 10.1.59- Upgrade to Apache Tomcat 9.0.121Note: This issue was fixed in Apache Tomcat 10.1.58 but the release vote for the 10.1.58 release candidate did not pass. Therefore, although users must download 10.1.59 to obtain a version that includes a fix for this issue, version 10.1.58 is not included in the list of affected versions.Credit:This issue was identified by:- 4ra1n, pyn3rd and unam4History:2026-08-25 Original advisoryReferences:[1] https://tomcat.apache.org/security-11.html[2] https://tomcat.apache.org/security-10.html[3] https://tomcat.apache.org/security-9.html
_________________________________________________________
NOTE: All exchanges posted to NSF Unidata maintained email lists are
made publicly available through the web. Users who post to any of the
lists we maintain are reminded to remove any personal information that
they do not want to be made public.
NSF Unidata thredds Mailing List
(
thr...@unidata.ucar.edu)
For list information, to unsubscribe, or change your membership options,
visit:
https://mailinglists.unidata.ucar.edu/listinfo/thredds/