OPENSUSE-SU-2026:20611-1
Vulnerability Summary
Timeline
Description
Security update for tomcat This update for tomcat fixes the following issues: - CVE-2026-24880: Request smuggling via invalid chunk extension (bsc#1261850). - CVE-2026-25854: Occasionally open redirect (bsc#1261851). - CVE-2026-29129: TLS cipher order is not preserved (bsc#1261852). - CVE-2026-29145: OCSP checks sometimes soft-fail even when soft-fail is disabled (bsc#1261853). - CVE-2026-29146,CVE-2026-34486: Fix for allowed bypass of EncryptInterceptor (bsc#1261854). - CVE-2026-34483: Incomplete escaping of JSON access logs (bsc#1261855). - CVE-2026-34487: Cloud membership for clustering component exposed the Kubernetes bearer token (bsc#1261856). - CVE-2026-34500: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled (bsc#1261857). - CVE-2026-32990: The fix for CVE-2025-66614 was incomplete. (bsc#1258371)
Affected Systems
- opensuse•tomcat&distro=openSUSE Leap 16.0
< 9.0.117-160000.1.1
References (20)
- https://bugzilla.suse.com/1258371
- https://bugzilla.suse.com/1261850
- https://bugzilla.suse.com/1261851
- https://bugzilla.suse.com/1261852
- https://bugzilla.suse.com/1261853
- https://bugzilla.suse.com/1261854
- https://bugzilla.suse.com/1261855
- https://bugzilla.suse.com/1261856
- https://bugzilla.suse.com/1261857
- https://www.suse.com/security/cve/CVE-2025-66614
- https://www.suse.com/security/cve/CVE-2026-24880
- https://www.suse.com/security/cve/CVE-2026-25854
- https://www.suse.com/security/cve/CVE-2026-29129
- https://www.suse.com/security/cve/CVE-2026-29145
- https://www.suse.com/security/cve/CVE-2026-29146
- https://www.suse.com/security/cve/CVE-2026-32990
- https://www.suse.com/security/cve/CVE-2026-34483
- https://www.suse.com/security/cve/CVE-2026-34486
- https://www.suse.com/security/cve/CVE-2026-34487
- https://www.suse.com/security/cve/CVE-2026-34500