Fwd: [thredds] [SECURITY] CVE-2026-65182 Apache Tomcat - Security constraint bypass

2 views
Skip to first unread message

Roy Mendelssohn - NOAA Federal

unread,
Aug 26, 2026, 9:54:26 AM (2 days ago) Aug 26
to erDDAP Bob Simons via, 'Micah Wengren' via ioos_tech
Please note and take appropriate action.

-Roy


Begin forwarded message:

From: Jennifer Oxelson Ganter <oxe...@ucar.edu>
Subject: [thredds] Fwd: [SECURITY] CVE-2026-65182 Apache Tomcat - Security constraint bypass
Date: August 26, 2026 at 6:49:32 AM PDT

Numerous CVEs of varying levels of severity have been issued for Tomcat.  Please upgrade to the latest version at your earliest convenience. 


Begin forwarded message:

From: Mark Thomas <ma...@apache.org>
Date: August 25, 2026 at 3:38:24 PM MDT
To: Tomcat Users List <us...@tomcat.apache.org>, anno...@tomcat.apache.org, anno...@apache.org, Tomcat Developers List <d...@tomcat.apache.org>
Subject: [SECURITY] CVE-2026-65182 Apache Tomcat - Security constraint bypass
Reply-To: anno...@tomcat.apache.org

CVE-2026-65182 Apache Tomcat - Security constraint bypass

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.24
Apache Tomcat 10.1.0-M1 to 10.1.57
Apache Tomcat 9.0.0.M1 to 9.0.120

Description:
The security constraint processing enabled a security constraint bypass if a constraint for a longer path was specified before a more restrictive constraint for a shorter sub-path.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Remove the examples web application
- Upgrade to Apache Tomcat 11.0.25
- Upgrade to Apache Tomcat 10.1.59
- Upgrade to Apache Tomcat 9.0.121

Note: This issue was fixed in Apache Tomcat 10.1.58 but the release vote for the 10.1.58 release candidate did not pass. Therefore, although users must download 10.1.59 to obtain a version that includes a fix for this issue, version 10.1.58 is not included in the list of affected versions.

Credit:
This issue was identified by:
- 4ra1n, pyn3rd and unam4

History:
2026-08-25 Original advisory

References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html

_________________________________________________________
NOTE: All exchanges posted to NSF Unidata maintained email lists are
made publicly available through the web. Users who post to any of the
lists we maintain are reminded to remove any personal information that
they do not want to be made public.

NSF Unidata thredds Mailing List
(thr...@unidata.ucar.edu)
For list information, to unsubscribe, or change your membership options,
visit: https://mailinglists.unidata.ucar.edu/listinfo/thredds/

Reply all
Reply to author
Forward
0 new messages