SUSE-SU-2026:3418-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263418-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3418-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3418-1
Upstream
CVE (2)
Related
Published
2026-07-30T07:07:42Z
Modified
2026-07-30T17:15:08Z
Summary
Security update for tomcat10
Details

This update for tomcat10 fixes the following issues:

Update to Tomcat 10.1.57.

Security issues fixed:

  • CVE-2026-59083: incorrect URL decoding in RewriteValve may allow security control bypass (bsc#1271397).
  • CVE-2026-59084: EncryptInterceptor requirements are not clearly documented (bsc#1271398).

Other updates and bugfixes:

  • Tomcat 10.1.57:
    • Catalina
      • Fix: Avoid a race condition with concurrent lookups for a singleton JNDI resource. (markt)
      • Fix: Improve the performance of range validation for the default servlet. (markt)
      • Fix: Avoid NPE in RewriteValve. (markt)
      • Fix: 70127: Fix use of Bootstrap through reflection by restoring the public constructor. Use through scripts was not affected. (remm)
      • Fix: Restore ability to extend many element classes from AbstractAccessLogValve. (remm)
      • Fix: Align DIGEST authentication with RFC 7616 and require clients to provide a valid qop parameter. (markt)
      • Fix: Use Files API to create temporary docBase when antiLockingDocBase is enabled. (markt)
      • Fix: Improve validation of configuration when DataSourceRealm starts. (remm)
      • Fix: JAASRealm should do a logout if login does not fail outright but does not produce a Principal. (remm)
      • Fix: Various edge cases for SSI substitutions, quoting and escaping. (remm)
      • Fix: unintentional conversion of literal + to a space during rule processing in the RewriteValve. (markt)
    • Coyote
      • Fix: Avoid a potential JVM crash if a suitable version of Tomcat Native is not available when the connector is explicitly configured to use Tomcat Native with OpenSSL for TLS. (markt)
    • Jasper
      • Fix: 70120: The fix for 69399 (itself a fix for a regression in the fix for 69333) was incomplete and tags that threw exceptions in doStartTag() and doEndTag() were incorrectly re-used. This fix prevents tags from being re-used if such an exception occurs. (markt)
      • Fix: 70135: Fix security classload regression. (remm)
      • Add: support for specifying Java 28 (with the value 28) as the compiler source and/or compiler target for JSP compilation. If used with an Eclipse JDT compiler version that does not support these values, a warning will be logged and the default will be used. (markt)
    • WebSocket
      • Fix: 70126: Fix WebSocket extension permessage-deflate so that it does not drop bytes if a compressed message inflates to more than the available buffer. Fix written by GPT-5.5. Test case written by Hironori Ichimiya. (markt)
      • Fix: Optimise WebSocket client processing of server responses during WebSocket HTTP upgrade process. (markt)
    • Other
      • Update: Byte Buddy to 1.18.9. (markt)
      • Update: UnboundID to 7.0.5. (markt)
      • Update: JaCoCo to 0.8.15. (markt)
      • Update: BND to 7.3.0. (markt)
      • Add: Improvements to French translations. (remm)
      • Add: Improvements to Japanese translations provided by tak7iji. (markt)
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
tomcat10

Package

Name
tomcat10
Purl
pkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.1.57-150200.5.73.1

Ecosystem specific

{
    "binaries":  [
        {
            "tomcat10":  "10.1.57-150200.5.73.1",
            "tomcat10-admin-webapps":  "10.1.57-150200.5.73.1",
            "tomcat10-el-5_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-jsp-3_1-api":  "10.1.57-150200.5.73.1",
            "tomcat10-lib":  "10.1.57-150200.5.73.1",
            "tomcat10-servlet-6_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-webapps":  "10.1.57-150200.5.73.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3418-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
tomcat10

Package

Name
tomcat10
Purl
pkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.1.57-150200.5.73.1

Ecosystem specific

{
    "binaries":  [
        {
            "tomcat10":  "10.1.57-150200.5.73.1",
            "tomcat10-admin-webapps":  "10.1.57-150200.5.73.1",
            "tomcat10-el-5_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-jsp-3_1-api":  "10.1.57-150200.5.73.1",
            "tomcat10-lib":  "10.1.57-150200.5.73.1",
            "tomcat10-servlet-6_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-webapps":  "10.1.57-150200.5.73.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3418-1.json"
SUSE:Linux Enterprise Module for Web and Scripting 15 SP7
tomcat10

Package

Name
tomcat10
Purl
pkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.1.57-150200.5.73.1

Ecosystem specific

{
    "binaries":  [
        {
            "tomcat10":  "10.1.57-150200.5.73.1",
            "tomcat10-admin-webapps":  "10.1.57-150200.5.73.1",
            "tomcat10-el-5_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-jsp-3_1-api":  "10.1.57-150200.5.73.1",
            "tomcat10-lib":  "10.1.57-150200.5.73.1",
            "tomcat10-servlet-6_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-webapps":  "10.1.57-150200.5.73.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3418-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
tomcat10

Package

Name
tomcat10
Purl
pkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.1.57-150200.5.73.1

Ecosystem specific

{
    "binaries":  [
        {
            "tomcat10":  "10.1.57-150200.5.73.1",
            "tomcat10-admin-webapps":  "10.1.57-150200.5.73.1",
            "tomcat10-el-5_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-jsp-3_1-api":  "10.1.57-150200.5.73.1",
            "tomcat10-lib":  "10.1.57-150200.5.73.1",
            "tomcat10-servlet-6_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-webapps":  "10.1.57-150200.5.73.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3418-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
tomcat10

Package

Name
tomcat10
Purl
pkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.1.57-150200.5.73.1

Ecosystem specific

{
    "binaries":  [
        {
            "tomcat10":  "10.1.57-150200.5.73.1",
            "tomcat10-admin-webapps":  "10.1.57-150200.5.73.1",
            "tomcat10-el-5_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-jsp-3_1-api":  "10.1.57-150200.5.73.1",
            "tomcat10-lib":  "10.1.57-150200.5.73.1",
            "tomcat10-servlet-6_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-webapps":  "10.1.57-150200.5.73.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3418-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
tomcat10

Package

Name
tomcat10
Purl
pkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.1.57-150200.5.73.1

Ecosystem specific

{
    "binaries":  [
        {
            "tomcat10":  "10.1.57-150200.5.73.1",
            "tomcat10-admin-webapps":  "10.1.57-150200.5.73.1",
            "tomcat10-el-5_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-jsp-3_1-api":  "10.1.57-150200.5.73.1",
            "tomcat10-lib":  "10.1.57-150200.5.73.1",
            "tomcat10-servlet-6_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-webapps":  "10.1.57-150200.5.73.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3418-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
tomcat10

Package

Name
tomcat10
Purl
pkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.1.57-150200.5.73.1

Ecosystem specific

{
    "binaries":  [
        {
            "tomcat10":  "10.1.57-150200.5.73.1",
            "tomcat10-admin-webapps":  "10.1.57-150200.5.73.1",
            "tomcat10-el-5_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-jsp-3_1-api":  "10.1.57-150200.5.73.1",
            "tomcat10-lib":  "10.1.57-150200.5.73.1",
            "tomcat10-servlet-6_0-api":  "10.1.57-150200.5.73.1",
            "tomcat10-webapps":  "10.1.57-150200.5.73.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3418-1.json"