Back Linuxsecurity openSUSE Tomcat11 Moderate Security Update for CVE-2026
- CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791).
- CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be
skipped if the first condition in an OR chain matched (bsc#1269910).
- CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824).
- CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints
to not be included when the effective web.xml was logged (bsc#1269909).
- CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster
component (bsc#1269908).
- CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any
method or method omission...
- openSUSE Leap 16.0:
tomcat11-11.0.23-160000.1.1
tomcat11-admin-webapps-11.0.23-160000.1.1
tomcat11-doc-11.0.23-160000.1.1
tomcat11-docs-webapp-11.0.23-160000.1.1
tomcat11-el-6_0-api-11.0.23-160000.1.1
tomcat11-embed-11.0.23-160000.1.1
tomcat11-jsp-4_0-api-11.0.23-160000.1.1
tomcat11-jsvc-11.0.23-160000.1.1
tomcat11-lib-11.0.23-160000.1.1
tomcat11-servlet-6_1-api-11.0.23-160000.1.1
tomcat11-webapps-11.0.23-160000.1.1
*
*
*
*
*
*
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
