Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
BIT-tomcat-2026-73180
  • Bitnami/tomcat
Apache Tomcat: Authenticated WebSocket session survives end of HTTP session 2 days ago
  • Fix available
  • Severity - 6.8 (Medium)
BIT-tomcat-2026-68763
  • Bitnami/tomcat
Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset 2 days ago
  • Fix available
  • Severity - 7.5 (High)
BIT-tomcat-2026-68569
  • Bitnami/tomcat
Apache Tomcat: Principal lookup can fail open in some cases 2 days ago
  • Fix available
  • Severity - 8.1 (High)
BIT-tomcat-2026-68525
  • Bitnami/tomcat
Apache Tomcat: Redirect after FORM auth may bypass method specific constraints 2 days ago
  • Fix available
  • Severity - 9.1 (Critical)
BIT-tomcat-2026-66422
  • Bitnami/tomcat
Apache Tomcat: Servlet role references can bypass declarative role constraints 2 days ago
  • Fix available
  • Severity - 8.1 (High)
BIT-tomcat-2026-65927
  • Bitnami/tomcat
Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control 2 days ago
  • Fix available
  • Severity - 7.5 (High)
BIT-tomcat-2026-65905
  • Bitnami/tomcat
Apache Tomcat: Limited replay attack possible with DIGEST authentication 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
BIT-tomcat-2026-65183
  • Bitnami/tomcat
Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets 2 days ago
  • Fix available
  • Severity - 8.1 (High)
BIT-tomcat-2026-65182
  • Bitnami/tomcat
Apache Tomcat: Bypass longest prefix security constraint 2 days ago
  • Fix available
  • Severity - 9.1 (Critical)
BIT-gitlab-2026-10053
  • Bitnami/gitlab
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab 2 days ago
  • Fix available
  • Severity - 8.5 (High)
BIT-tomcat-2026-65637
  • Bitnami/tomcat
Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
BIT-vault-2026-5006
  • Bitnami/vault
Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths 2 days ago
  • Fix available
  • Severity - 6.8 (Medium)
BIT-grafana-2026-17033
  • Bitnami/grafana
CVE-2026-17033 CVE Record 2 days ago
  • Fix available
  • Severity - 6.8 (Medium)
BIT-gitea-2026-60004
  • Bitnami/gitea
See record for full details 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
BIT-apisix-2026-63041
  • Bitnami/apisix
Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers 2 days ago
  • Fix available
  • Severity - 5.3 (Medium)
BIT-neo4j-enterprise-2026-1524
  • Bitnami/neo4j-enterprise
Auth misconfiguration when multiple providers enabled 3 days ago
  • Fix available
  • Severity - 2.1 (Low)