[CLSA-2026:1784625369] tomcat: Fix of CVE-2026-59083
Type:
security
Severity:
Moderate
Release date:
2026-07-21 09:16:34 UTC
Description:
- CVE-2026-59083: decode the rewritten URL with Tomcat's UDecoder.URLDecode() instead of java.net.URLDecoder in the RewriteValve, fixing improper URL (hex) encoding handling that could bypass security constraints for some configurations (upstream tomcat 9.0.120)
CVEs fixed:
Updated packages:
  • tomcat-9.0.87-3.el9_6.3.tuxcare.els10.noarch.rpm
    sha:418337df0a3a253664980d6fdc7b70e3ae339cdfcd37a464b191ae8a129d7c87
  • tomcat-admin-webapps-9.0.87-3.el9_6.3.tuxcare.els10.noarch.rpm
    sha:c6c7a120a9825d90307e02139f7a353748a3b67c3b256080c9f2b1af6be2a1a6
  • tomcat-docs-webapp-9.0.87-3.el9_6.3.tuxcare.els10.noarch.rpm
    sha:3e9d2f277db6b3d7a3b66ba462c15815604138598410505a0c9121d1220fd53c
  • tomcat-el-3.0-api-9.0.87-3.el9_6.3.tuxcare.els10.noarch.rpm
    sha:c36ad5ee4576d76ce7081a432e3c45692bc0a1f0b6855b94e61f79de64ac1573
  • tomcat-jsp-2.3-api-9.0.87-3.el9_6.3.tuxcare.els10.noarch.rpm
    sha:0c017a8dcaa977423b94e2acad668c626cd63dec6cbbcd09a6447aba0c6849f6
  • tomcat-lib-9.0.87-3.el9_6.3.tuxcare.els10.noarch.rpm
    sha:4ae5daa25ea5d5c1b6fd6c64749ca92da08c74c4a9fb597600c0fd44d18ce888
  • tomcat-servlet-4.0-api-9.0.87-3.el9_6.3.tuxcare.els10.noarch.rpm
    sha:4c76888d245a0cf9cda827be014fc676cca6e8a8e147068f5d2acfc6697fb30b
  • tomcat-webapps-9.0.87-3.el9_6.3.tuxcare.els10.noarch.rpm
    sha:8d8c047a1db4caa8e9e071b629ef2aa4a5afaca82f734c0d07a75decdf58d5d8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.