Release date:
2026-08-10 09:09:59 UTC
Description:
* SECURITY UPDATE: Security constraint bypass in the RewriteValve - the
decoded and normalized request URI used for subsequent security
constraint matching was produced with java.net.URLDecoder.decode(),
which applies form-encoding rules and converts '+' to a space instead
of performing proper URI percent-decoding
- debian/patches/CVE-2026-59083.patch: use Tomcat's UDecoder.URLDecode()
(already imported and used elsewhere in the class) instead of
java.net.URLDecoder.decode() to build the decoded request URI
- CVE-2026-59083
Updated packages:
-
libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els7_all.deb
sha:9c2e795e234da0c126de6dd799860f35885f74f1
-
libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els7_all.deb
sha:784f57a117fd056f21a65c9f719c785997af32de
-
tomcat9_9.0.31-1~deb10u12+tuxcare.els7_all.deb
sha:3d0bd84f880e15a50c5a574671e074e641ce8adc
-
tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els7_all.deb
sha:22e44c8187f207c498692cd7f19a88d64cdaaf70
-
tomcat9-common_9.0.31-1~deb10u12+tuxcare.els7_all.deb
sha:2941768d2dad38baf1c031d5cec65e5cca9e9db6
-
tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els7_all.deb
sha:ac020c46dfa112cb1f22d63e9f754263eb3439f5
-
tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els7_all.deb
sha:88817701f4fffbb1f9073b5d987a8fa987660082
-
tomcat9-user_9.0.31-1~deb10u12+tuxcare.els7_all.deb
sha:8fc4e8a9265caff22fc079ca5e4272da7589b844
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.