Skip to content
openSUSE tomcat11 Important DoS Exploit Issues Fixed 2026-4114

openSUSE tomcat11 Important DoS Exploit Issues Fixed 2026-4114

Linuxsecurity •LinuxSecurity Advisories • September 10, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

This update for tomcat11 fixes the following issues:

* CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint

* CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for

Unix Domain Sockets (bsc#1276894).

* CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI

validation - fix incomplete (bsc#1276895).

* CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST

authentication (bsc#1276896).

* CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule

and may bypass access control (bsc#1276897).

* CVE-2026-66299: memory exhaustion via maliciously slow clients due to the

WebSocket chat example providing an unbounded buffer for undelivered

messages (bsc#1273150).

* CVE-2026-66422: Apache Tomcat: Servlet role references can bypass

declarative role constraints (bsc#1276898).

* CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may...

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4114=1

zypper in -t patch SUSE-2026-4114=1

* Web and Scripting Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-4114=1

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4114=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)

* tomcat11-lib-11.0.25-150600.13.33.2

* tomcat11-admin-webapps-11.0.25-150600.13.33.2

* tomcat11-servlet-6_1-api-11.0.25-150600.13.33.2

* tomcat11-el-6_0-api-11.0.25-150600.13.33.2

* tomcat11-webapps-11.0.25-150600.13.33.2

* tomcat11-jsp-4_0-api-11.0.25-150600.13.33.2

* tomcat11-11.0.25-150600.13.33.2

* openSUSE Leap 15.6 (noarch)

* tomcat11-lib-11.0.25-150600.13.33.2

* tomcat11-admin-webapps-11.0.25-150600.13.33.2

* tomcat11-embed-11.0.25-150600.13.33.2

* tomcat11-servlet-6_1-api-11.0.25-150600.13.33.2

* tomcat11-el-6_0-api-11.0.25-150600.13.33.2

* tomcat11-jsvc-11.0.25-150600.13.33.2

* tomcat11-docs-webapp-11.0.25-150600.13.33.2

* tomcat11-webapps-11.0.25-150600.13.33.2

* tomcat11-doc-11.0.25-150600.13.33.2

* tomcat11-jsp-4_0-api-11.0.25-150600.13.33.2

* tomcat11-11.0.25-150600.13.33.2

* Web and Scripting Module 15-SP7 (noarch)

* tomcat11-lib-11.0.25-150600.13.33.2

* tomcat11-admin-webapps-11.0.25-150600.13.33.2

*

*

*

*

*

*

*

*

*

*

*

*

*

*

*

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases