Back Linuxsecurity SUSE Tomcat10 Major Security Update 11 Vulnerabilities Resolved 2026-4119
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
## This update for tomcat10 fixes the following issues: * CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150).
## This update for tomcat10 fixes the following issues: * CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150).
* CVE-2026-65182 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Announcement ID: SUSE-SU-2026:4119-1 Release Date: 2026-09-10T08:16:51Z Rating: important
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
