Ce mail provient de l'extérieur, restons vigilants

=====================================================================

                            CERT-Renater

                Note d'Information No. 2026/VULN695
_____________________________________________________________________

DATE                : 30/06/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache Tomcat versions prior to
                             11.0.23, 10.1.56, 9.0.119.
 
=====================================================================
https://lists.apache.org/thread/j5s5pdyr5fwp1s96hmc398tn6k0gbsc5
https://lists.apache.org/thread/9y0gjcjjmoq2xl91tz7botgxn6mpw6ls
https://lists.apache.org/thread/zfxycp2d0yb4p9vdgbjctr1l06kc91jn
https://lists.apache.org/thread/7j8pvjjgflg7tob30gbc0x2dhnbdzw7j
https://lists.apache.org/thread/jknt7rnm719kkkvbfvq0mf189njlj8f3
https://lists.apache.org/thread/3vw19bkso2sskws2h2hz44m7hmt6d5hf
https://lists.apache.org/thread/0yx97bhlyqrk7wlrlpgo88jg9yw3n6v2
_____________________________________________________________________

CVE-2026-55957 Apache Tomcat - Authentication bypass with JNDIRealm
and GSSAPI authenticated bind

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.4
Apache Tomcat 10.1.0-M1 to 10.1.36
Apache Tomcat 9.0.0.M1 to 9.0.100
Older, unsupported versions may also be affected

Description:
If security constraints were specified for the default servlet, any 
method or method omission configured as part of the constraint was
ignored.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 11.0.5 or later
- Upgrade to Apache Tomcat 10.1.37 or later
- Upgrade to Apache Tomcat 9.0.101 or later

Credit:
This issue was identified by:
- Ilan Toyter

History:
2026-06-29 Original advisory

References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html

_____________________________________________________________________

CVE-2026-55956 Apache Tomcat - Security constraints for default
servlet

ignored method

Severity: Moderate

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.22
Apache Tomcat 10.1.0-M1 to 10.1.55
Apache Tomcat 9.0.0.M1 to 9.0.118
Older, unsupported versions may also be affected

Description:
If security constraints were specified for the default servlet, any 
method or method omission configured as part of the constraint was
ignored.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 11.0.23 or later
- Upgrade to Apache Tomcat 10.1.56 or later
- Upgrade to Apache Tomcat 9.0.119 or later

Credit:
This issue was identified by:
- j0hndo (dohyun4466@gmail.com)

History:
2026-06-29 Original advisory

References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html

_____________________________________________________________________

CVE-2026-55955 Apache Tomcat - EncryptInterceptor not protected
against replay attacks

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.22
Apache Tomcat 10.1.0-M1 to 10.1.55
Apache Tomcat 9.0.13 to 9.0.118
Older, unsupported versions may also be affected

Description:
Contrary to the documentation, the EncryptInterceptor was not
protected against replay attacks.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 11.0.23 or later
- Upgrade to Apache Tomcat 10.1.56 or later
- Upgrade to Apache Tomcat 9.0.119 or later

History:
2026-06-29 Original advisory

References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html

_____________________________________________________________________

CVE-2026-55276 Apache Tomcat - Logged effective web.xml is incomplete

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.22
Apache Tomcat 10.1.0-M1 to 10.1.55
Apache Tomcat 9.0.0.M1 to 9.0.118
Older, unsupported versions may also be affected

Description:
Logic errors in the effective web.xml generation meant that neither 
special roles nor empty authorization constraints were included in
the logged effective web.xml.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 11.0.23 or later
- Upgrade to Apache Tomcat 10.1.56 or later
- Upgrade to Apache Tomcat 9.0.119 or later

History:
2026-06-29 Original advisory

References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html

_____________________________________________________________________

CVE-2026-53434 Apache Tomcat - Invalid CRL configuration doesn't
trigger failure for FFM Connector

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.22
Apache Tomcat 10.1.0-M7 to 10.1.55
Apache Tomcat 9.0.83 to 9.0.118
Older, unsupported versions may also be affected

Description:
If an FFM connector was configured with invalid CRLs, the invalid
CRLs were ignored meaning invalid certificates could be accepted.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 11.0.23 or later
- Upgrade to Apache Tomcat 10.1.56 or later
- Upgrade to Apache Tomcat 9.0.119 or later

History:
2026-06-29 Original advisory

References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html

_____________________________________________________________________

CVE-2026-53404 Apache Tomcat - Bad ornext processing in RewriteValve

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.22
Apache Tomcat 10.1.0-M1 to 10.1.55
Apache Tomcat 9.0.0.M1 to 9.0.118
Older, unsupported versions may also be affected

Description:
If a request matched the first condition in an OR chain, subsequent 
non-OR conditions were skipped and the rewrite succeeded.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 11.0.23 or later
- Upgrade to Apache Tomcat 10.1.56 or later
- Upgrade to Apache Tomcat 9.0.119 or later

History:
2026-06-29 Original advisory

References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html

_____________________________________________________________________

[SECURITY] CVE-2026-50229 Apache Tomcat - XXS in number guess example
CVE-2026-50229 Apache Tomcat - XXS in number guess example

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.22
Apache Tomcat 10.1.0-M1 to 10.1.55
Apache Tomcat 9.0.0.M1 to 9.0.118
Older, unsupported versions may also be affected

Description:
The use of wild card property mapping resulted in some properties, that 
were intended to be internal only, being exposed to clients allowing an 
XSS attack.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 11.0.23 or later
- Upgrade to Apache Tomcat 10.1.56 or later
- Upgrade to Apache Tomcat 9.0.119 or later

Credit:
This issue was identified by:
- Erichen, Institute of Computing Technology, Chinese Academy of
    Sciences
- Yashar Shahinzadeh
- Amirmohammad Safari

History:
2026-06-29 Original advisory

References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




