<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<!-- MHonArc v2.6.19+ -->
  <channel>
    <title>announce</title>
    <link>http://www.mail-archive.com/announce@tomcat.apache.org</link>
    <description>announce @ tomcat.apache</description>
    <pubDate>Thu, 09 Apr 2026 19:35:52 GMT</pubDate>
    <lastBuildDate>Thu, 09 Apr 2026 19:35:52 GMT</lastBuildDate>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <generator>MHonArc RSS 2.0 RCFile</generator>
    <webMaster>themailarchive@gmail.com (The Mail Archive)</webMaster>
    <image>
       <title>The Mail Archive</title>
       <url>http://www.mail-archive.com/nanologo.png</url>
       <link>http://www.mail-archive.com/announce@tomcat.apache.org</link>
    </image>
 
    <item>
      <title>[SECURITY] CVE-2026-34500 Apache Tomcat - OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00772.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:35:51 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00772.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2026-34486 Apache Tomcat - Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00771.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:34:25 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00771.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2026-34483 Apache Tomcat - Incomplete escaping of JSON access logs</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00770.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:33:23 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00770.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2026-34487 Apache Tomcat - Cloud membership for clustering component exposed the Kubernetes bearer token</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00769.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:28:37 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00769.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2026-32990 Apache Tomcat - The fix for CVE-2025-66614 is incomplete</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00768.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:27:31 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00768.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2026-29129 Apache Tomcat - Configured TLS cipher preference order not preserved</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00767.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:17:36 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00767.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2026-29145 Apache Tomcat and Tomcat Native - OCSP checks sometimes soft-fail even when soft-fail is disabled</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00766.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:17:26 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00766.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2026-29146 Apache Tomcat - EncryptInterceptor vulnerable to padding oracle attack by default</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00765.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:16:27 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00765.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2026-24880 Apache Tomcat - Request smuggling via invalid chunk extension</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00764.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:12:27 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00764.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2026-25854 Apache Tomcat - Occasionally open redirect</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00763.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:12:08 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00763.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.21 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00762.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/04&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Sat, 04 Apr 2026 12:05:36 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00762.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.117 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00761.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/03&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Fri, 03 Apr 2026 09:28:06 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00761.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.54 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00760.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/03&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Fri, 03 Apr 2026 07:29:40 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00760.html</guid>
   </item>
    <item>
      <title>[ANN] End Of Support for Tomcat Native 1.x</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00759.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/04/03&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Fri, 03 Apr 2026 07:24:52 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00759.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.53 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00758.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/03/24&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Tue, 24 Mar 2026 07:58:14 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00758.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.116 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00757.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/03/20&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Fri, 20 Mar 2026 14:56:05 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00757.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.20 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00756.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/03/20&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Fri, 20 Mar 2026 12:18:49 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00756.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat Native 1.3.7 released</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00755.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/03/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Tue, 10 Mar 2026 10:46:00 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00755.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat Native 2.0.14 released</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00754.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/03/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Tue, 10 Mar 2026 10:44:38 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00754.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2026-24733 Apache Tomcat - Security constraint bypass with HTTP/0.9</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00753.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Tue, 17 Feb 2026 18:30:50 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00753.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2026-24734 Apache Tomcat and Tomcat Native - OCSP revocation bypass</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00752.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Tue, 17 Feb 2026 18:26:41 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00752.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-66614 Apache Tomcat - Client certificate verification bypass due to virtual host mapping</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00751.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Tue, 17 Feb 2026 18:24:00 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00751.html</guid>
   </item>
    <item>
      <title>[ANN] End of support for Apache Tomcat Native 1.3.x</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00750.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Wed, 11 Feb 2026 12:29:36 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00750.html</guid>
   </item>
    <item>
      <title>[ANN] Tomcat 9.0.x End of Support and Tomcat 9 long term support plan</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00749.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Wed, 11 Feb 2026 12:25:12 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00749.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat Native 1.3.6 released</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00748.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Wed, 11 Feb 2026 11:45:20 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00748.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat Native 2.0.13 released</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00747.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Wed, 11 Feb 2026 10:13:28 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00747.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.18 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00746.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/01/30&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Fri, 30 Jan 2026 10:12:46 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00746.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.52 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00745.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/01/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Wed, 28 Jan 2026 10:00:32 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00745.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.115 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00744.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/01/23&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Fri, 23 Jan 2026 16:09:16 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00744.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat Native 1.3.4 released</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00743.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/01/12&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 12 Jan 2026 12:11:31 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00743.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat Native 2.0.12 released</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00742.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/01/12&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 12 Jan 2026 12:09:17 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00742.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.50 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00741.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/12/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Tue, 09 Dec 2025 08:29:04 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00741.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.15 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00740.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/12/08&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 08 Dec 2025 09:30:47 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00740.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.113 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00739.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/12/07&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Sun, 07 Dec 2025 15:40:25 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00739.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat Migration tool for Jakarta EE 1.0.10</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00738.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/11/24&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 24 Nov 2025 22:39:39 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00738.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.49 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00737.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/11/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Tue, 11 Nov 2025 07:32:29 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00737.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.112 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00736.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/11/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Mon, 10 Nov 2025 16:09:20 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00736.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.14 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00735.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/11/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 10 Nov 2025 15:44:24 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00735.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-61795 Apache Tomcat - Delayed cleaning of multipart upload temporary files may lead to DoS</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00734.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/10/27&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 27 Oct 2025 17:20:55 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00734.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-55752 Apache Tomcat - Directory traversal via rewrite with possible RCE if PUT is enabled</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00733.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/10/27&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 27 Oct 2025 17:18:27 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00733.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-55754 Apache Tomcat - Console manipulation via escape sequences in log messages</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00732.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/10/27&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 27 Oct 2025 17:15:24 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00732.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.110 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00731.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/10/18&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Sat, 18 Oct 2025 17:58:20 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00731.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.12 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00730.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/10/18&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Sat, 18 Oct 2025 04:55:12 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00730.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.47 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00729.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/10/18&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Sat, 18 Oct 2025 03:28:17 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00729.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.13 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00728.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/10/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Fri, 17 Oct 2025 22:43:49 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00728.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.48 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00727.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/10/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Fri, 17 Oct 2025 18:31:26 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00727.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.111 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00726.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/10/13&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Mon, 13 Oct 2025 20:43:57 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00726.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.46 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00725.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/09/12&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Fri, 12 Sep 2025 14:13:23 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00725.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.45 Available (with IMPORTANT NOTE)</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00724.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/09/08&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Mon, 08 Sep 2025 14:26:23 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00724.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.11 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00723.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/09/07&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Sun, 07 Sep 2025 16:26:50 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00723.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.109 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00722.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/09/06&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Sat, 06 Sep 2025 01:22:11 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00722.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-55668 Apache Tomcat - Session fixation via rewrite valve</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00721.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/08/13&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Wed, 13 Aug 2025 13:16:49 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00721.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-48989 Apache Tomcat - DoS in HTP/2 - Made You Reset</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00720.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/08/13&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Wed, 13 Aug 2025 12:09:12 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00720.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.44 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00719.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/08/07&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Thu, 07 Aug 2025 18:41:50 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00719.html</guid>
   </item>
    <item>
      <title>[SECURITY] Upcoming updates to recent(ish)Tomcat CVEs</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00718.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/08/07&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 07 Aug 2025 10:42:54 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00718.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.10 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00717.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/08/07&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 07 Aug 2025 08:43:56 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00717.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.108 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00716.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/08/06&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Wed, 06 Aug 2025 17:56:55 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00716.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-52520 Apache Tomcat - DoS in multipart upload [CORRECTION]</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00715.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Fri, 11 Jul 2025 18:50:02 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00715.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-52520 Apache Tomcat - DoS in multipart upload</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00714.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jul 2025 19:25:33 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00714.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-53506 Apache Tomcat - DoS in HTP/2</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00713.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jul 2025 19:23:43 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00713.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-53506 Apache Tomcat - DoS in HTP/2</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00712.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jul 2025 19:03:49 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00712.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-52520 Apache Tomcat - DoS in multipart upload</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00711.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jul 2025 19:01:04 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00711.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-52434 Apache Tomcat -APR/native Connector crash leading to DoS</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00710.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jul 2025 18:59:05 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00710.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.107 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00709.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/04&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Fri, 04 Jul 2025 21:03:55 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00709.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.9 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00708.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/04&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Fri, 04 Jul 2025 20:11:29 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00708.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.43 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00707.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/04&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Fri, 04 Jul 2025 20:05:06 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00707.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-49124 Apache Tomcat - Side-loading via Tomcat installer for Windows</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00706.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/06/16&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 16 Jun 2025 14:20:39 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00706.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-49125 Apache Tomcat - Security constraint bypass for pre/post-resources</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00705.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/06/16&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 16 Jun 2025 14:15:12 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00705.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-48988 Apache Tomcat - DoS in multipart upload</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00704.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/06/16&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 16 Jun 2025 14:09:03 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00704.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-48976 Apache Tomcat - DoS in Commons FileUpload</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00703.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/06/16&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 16 Jun 2025 14:06:36 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00703.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.8 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00702.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/06/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Tue, 10 Jun 2025 10:43:10 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00702.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.106 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00701.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/06/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Tue, 10 Jun 2025 08:38:40 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00701.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.42 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00700.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/06/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Tue, 10 Jun 2025 06:57:16 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00700.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-46701 Apache Tomcat - CGI security constraint bypass</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00699.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/05/29&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Thu, 29 May 2025 19:04:58 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00699.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.105 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00698.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/05/12&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Mon, 12 May 2025 21:05:56 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00698.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.41 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00697.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/05/12&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Mon, 12 May 2025 17:38:02 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00697.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-31651 Apache Tomcat - Rewrite rule bypass</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00696.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/04/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 28 Apr 2025 19:13:48 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00696.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-31650 Apache Tomcat - DoS via invalid HTTP prioritization header</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00695.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/04/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 28 Apr 2025 19:11:22 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00695.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.104 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00694.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/04/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Wed, 09 Apr 2025 21:19:52 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00694.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2025-24813 Potential RCE and/or information disclosure and/or information corruption with partial PUT</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00693.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/03/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Tue, 11 Mar 2025 17:05:43 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00693.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.102 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00692.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/03/06&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Thu, 06 Mar 2025 20:24:03 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00692.html</guid>
   </item>
    <item>
      <title>The future of Tomcat 9</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00691.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/02/25&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Tue, 25 Feb 2025 10:47:29 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00691.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.100 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00690.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/02/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Mon, 17 Feb 2025 13:55:57 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00690.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.4 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00689.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/02/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 17 Feb 2025 10:45:58 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00689.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.3 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00688.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/02/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 10 Feb 2025 16:11:04 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00688.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.99 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00687.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/02/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Mon, 10 Feb 2025 15:55:51 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00687.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat Migration tool for Jakarta EE 1.0.9</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00686.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/01/21&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Tue, 21 Jan 2025 08:44:54 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00686.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2024-56337 Apache Tomcat - RCE via write-enabled default servlet - CVE-2024-50379 mitigation was incomplete</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00685.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/12/20&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Fri, 20 Dec 2024 15:27:56 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00685.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2024-54677 Apache Tomcat - DoS in examples web application</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00684.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/12/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Tue, 17 Dec 2024 12:32:50 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00684.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2024-50379 Apache Tomcat - RCE via write-enabled default servlet</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00683.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/12/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Tue, 17 Dec 2024 12:27:45 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00683.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.98 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00682.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/12/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Mon, 09 Dec 2024 15:04:19 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00682.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.2 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00681.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/12/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 09 Dec 2024 13:21:31 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00681.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2024-52316 Apache Tomcat - Authentication Bypass</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00680.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/11/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Tue, 19 Nov 2024 01:13:50 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00680.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2024-52317 Apache Tomcat - Request and/or response mix-up</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00679.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/11/18&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 18 Nov 2024 14:12:35 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00679.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2024-52318 Apache Tomcat - XSS in generated JSPs</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00678.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/11/18&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 18 Nov 2024 12:19:02 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00678.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2024-52317 Apache Tomcat - Request and/or response mix-up</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00677.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/11/18&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Mon, 18 Nov 2024 11:23:55 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00677.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 10.1.33 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00676.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/11/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Christopher Schultz%22&quot;&gt;Christopher Schultz&lt;/a&gt;</description>
      <pubDate>Mon, 11 Nov 2024 15:26:33 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00676.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.97 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00675.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/11/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Sat, 09 Nov 2024 14:08:38 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00675.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 11.0.0 Available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00674.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/10/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Mark Thomas%22&quot;&gt;Mark Thomas&lt;/a&gt;</description>
      <pubDate>Wed, 09 Oct 2024 17:09:19 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00674.html</guid>
   </item>
    <item>
      <title>[ANN] Apache Tomcat 9.0.96 available</title>
      <link>http://www.mail-archive.com/announce@tomcat.apache.org/msg00673.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/10/08&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@tomcat.apache.org&amp;q=from:%22Rémy Maucherat%22&quot;&gt;Rémy Maucherat&lt;/a&gt;</description>
      <pubDate>Tue, 08 Oct 2024 13:37:20 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@tomcat.apache.org/msg00673.html</guid>
   </item>
 
  </channel>
  </rss>
<!-- MHonArc v2.6.19+ -->
