Skip to content
SUSE Tomcat10 Major Security Update 11 Vulnerabilities Resolved 2026-4119

SUSE Tomcat10 Major Security Update 11 Vulnerabilities Resolved 2026-4119

Linuxsecurity •LinuxSecurity Advisories • September 10, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

## This update for tomcat10 fixes the following issues: * CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150).

## This update for tomcat10 fixes the following issues: * CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150).

* CVE-2026-65182 ( SUSE ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

* CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

* CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Announcement ID: SUSE-SU-2026:4119-1 Release Date: 2026-09-10T08:16:51Z Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases