Several security vulnerabilities have been found in Tomcat 10, a Java web server and servlet engine. This update improves the handling of HTTP/2 connections and corrects various flaws which can lead to uncontrolled resource consumption and a denial of service. For the oldstable distribution (bookworm), these problems have been fixed in version 10.1.52-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 10.1.52-1~deb13u1. We recommend that you upgrade your tomcat10 packages. For the detailed security status of tomcat10 please refer to its security tracker page at: Further information Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at:
Several security vulnerabilities have been found in Tomcat 10, a Java web server and servlet engine. This update improves the handling of HTTP/2 connections and corrects various flaws which can lead to uncontrolled resource consumption and a denial of service. For the oldstable distribution (bookworm), these problems have been fixed in version 10.1.52-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 10.1.52-1~deb13u1. We recommend that you upgrade your tomcat10 packages. For the detailed security status of tomcat10 please refer to its security tracker page at: Further information Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
