These are all security issues fixed in the tomcat-9.0.36-8.4 package on the GA media of openSUSE Tumbleweed.
{ "binaries": [ { "tomcat-lib": "9.0.36-8.4", "tomcat-jsvc": "9.0.36-8.4", "tomcat-webapps": "9.0.36-8.4", "tomcat-embed": "9.0.36-8.4", "tomcat-docs-webapp": "9.0.36-8.4", "tomcat-servlet-4_0-api": "9.0.36-8.4", "tomcat": "9.0.36-8.4", "tomcat-el-3_0-api": "9.0.36-8.4", "tomcat-admin-webapps": "9.0.36-8.4", "tomcat-javadoc": "9.0.36-8.4", "tomcat-jsp-2_3-api": "9.0.36-8.4" } ] }