[CLSA-2026:1786352989] Fix CVE(s): CVE-2026-59083
Type:
security
Severity:
Moderate
Release date:
2026-08-10 09:09:59 UTC
Description:
* SECURITY UPDATE: Security constraint bypass in the RewriteValve - the decoded and normalized request URI used for subsequent security constraint matching was produced with java.net.URLDecoder.decode(), which applies form-encoding rules and converts '+' to a space instead of performing proper URI percent-decoding - debian/patches/CVE-2026-59083.patch: use Tomcat's UDecoder.URLDecode() (already imported and used elsewhere in the class) instead of java.net.URLDecoder.decode() to build the decoded request URI - CVE-2026-59083
CVEs fixed:
Updated packages:
  • libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els7_all.deb
    sha:9c2e795e234da0c126de6dd799860f35885f74f1
  • libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els7_all.deb
    sha:784f57a117fd056f21a65c9f719c785997af32de
  • tomcat9_9.0.31-1~deb10u12+tuxcare.els7_all.deb
    sha:3d0bd84f880e15a50c5a574671e074e641ce8adc
  • tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els7_all.deb
    sha:22e44c8187f207c498692cd7f19a88d64cdaaf70
  • tomcat9-common_9.0.31-1~deb10u12+tuxcare.els7_all.deb
    sha:2941768d2dad38baf1c031d5cec65e5cca9e9db6
  • tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els7_all.deb
    sha:ac020c46dfa112cb1f22d63e9f754263eb3439f5
  • tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els7_all.deb
    sha:88817701f4fffbb1f9073b5d987a8fa987660082
  • tomcat9-user_9.0.31-1~deb10u12+tuxcare.els7_all.deb
    sha:8fc4e8a9265caff22fc079ca5e4272da7589b844
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.