Release date:
2026-06-05 08:56:53 UTC
Description:
* SECURITY UPDATE: fix the handling of invalid users with DIGEST authentication
- debian/patches/CVE-2026-43512.patch: fix the handling of invalid users with DIGEST authentication
- CVE-2026-43512
* SECURITY UPDATE: add case sensitive attribute to LockOutRealm
- debian/patches/CVE-2026-43513.patch: add case sensitive attribute to LockOutRealm
- CVE-2026-43513
* SECURITY UPDATE: switch AJP secret comparison to a constant time algorithm
- debian/patches/CVE-2026-43514.patch: switch AJP secret comparison to a constant time algorithm
- CVE-2026-43514
* SECURITY UPDATE: ensure RealmBase finds all matching extension based constraints
- debian/patches/CVE-2026-43515.patch: ensure RealmBase finds all matching extension based constraints
- CVE-2026-43515
* SECURITY UPDATE: add a configurable limit for WebDAV XML request bodies
- debian/patches/CVE-2026-41284.patch: add a configurable limit for WebDAV XML request bodies
- CVE-2026-41284
* SECURITY UPDATE: fix WebSocket + proxy + DIGEST auth on proxy
- debian/patches/CVE-2026-42498.patch: fix WebSocket + proxy + DIGEST auth on proxy
- CVE-2026-42498
* SECURITY UPDATE: HTTP/2 header filtering - validate decoded HPACK names/values against RFC 7230 token/field-vchar/field-content rules
- debian/patches/CVE-2026-41293.patch: HTTP/2 header filtering - validate decoded HPACK names/values against RFC 7230 token/field-vchar/field-content rules
- CVE-2026-41293
* Build: refresh debian/test_certs/ test fixtures (CA + RSA/EC server
certs + client cert) — upstream localhost-rsa.jks is expired since
2025-02-16 and 8.5.x is no longer rotated; new fixtures are signed
by a fresh self-signed CA with 10-year validity, applied via the
existing TEST_CERTS_DIR overlay in debian/rules.
Updated packages:
-
libtomcat8-embed-java_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
sha:dfadbc547ef9e8e85824d565c4244ce2f49b4293
-
libtomcat8-java_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
sha:3e2d4d92ca3abfec6d1b7ee03bcceeac8c6e590e
-
tomcat8_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
sha:045418c97d47b39532a4a8c7ad40aa477c2b26e2
-
tomcat8-admin_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
sha:df0164c53ea02d84b8e3788e15cb1969e8cec166
-
tomcat8-common_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
sha:20616509c062c3e07dfc9c56efa9b4373114aa92
-
tomcat8-docs_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
sha:c0cc65bbb9af6ffefc7b9e559b93d59b60cd0675
-
tomcat8-examples_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
sha:a5fb720d2a9fd13749e5ac5fb0fc3af5812de8ba
-
tomcat8-user_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
sha:166635290bcb5db6baac0aed1cfe2cdd9874dfb5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.