Corruption of files uploaded with Safari when Tomcat has HTTP/2 enabled

2025-07-18 Thread Clint Carrion
Hi, I’ve discovered that in my web application files that are uploaded via a form with Safari (v18.5) and Tomcat (v11.0.9) has HTTP/2 enabled, they're being corrupted. If I use Chrome (v137.0.7151.122) they upload without error and if I disable HTTP/2 on Tomcat, the files will upload wi

Re: Server Vulnerabilities for Apache Tomcat 9.0.0.M1 < 9.0.98

2025-07-17 Thread Christopher Schultz
Hassan, On 7/17/25 1:04 PM, Jacobs, Hassan wrote: I am reaching out in regards to multiple vulnerabilities that we have found in our servers with you all. Is there a representative that we could speak with? You're speaking to the whole community. The ASF does not provide support through any

Re: Server Vulnerabilities for Apache Tomcat 9.0.0.M1 < 9.0.98

2025-07-17 Thread Robert Turner
If you haven't already, you should review: https://tomcat.apache.org/security-9.html Also consider migrating / upgrading to the most recent 9.0.x version. On Thu, Jul 17, 2025 at 1:05 PM Jacobs, Hassan wrote: > Greetings, > > > > I am reaching out in regards to multiple vulnerabilities that we

Server Vulnerabilities for Apache Tomcat 9.0.0.M1 < 9.0.98

2025-07-17 Thread Jacobs, Hassan
Greetings, I am reaching out in regards to multiple vulnerabilities that we have found in our servers with you all. Is there a representative that we could speak with? Very Respectfully, Hassan Jacobs SAP Analyst EZGO [cid:image001.png@01DBF71B.566B1E80]

Re: RHEL 10 Compatibility for Apache Tomcat 8.x, 9.x, 10.x, and 11.x

2025-07-16 Thread Coty Sutherland
Just wanted to +1 to Chris' comments as one of the folks Chris was referring to in the community :) I'd also add that Red Hat also runs lots of regression tests, integration tests, testing layered products that use tomcat, etc. that ensure the packaged version of tomcat works without

Re: RHEL 10 Compatibility for Apache Tomcat 8.x, 9.x, 10.x, and 11.x

2025-07-15 Thread Christopher Schultz
Bharath, On 7/15/25 3:11 AM, Cheruku, B.R. (Bharath) wrote: Thank you for your detailed response and the helpful information regarding Tomcat on RHEL 10. As a follow-up, do you or anyone in the community have similar insights or recommendations regarding running Apache HTTPD (httpd) on RHEL 10

Re: RHEL 10 Compatibility for Apache Tomcat 8.x, 9.x, 10.x, and 11.x

2025-07-15 Thread Cheruku, B.R. (Bharath)
Hi Chris, Thank you for your detailed response and the helpful information regarding Tomcat on RHEL 10. As a follow-up, do you or anyone in the community have similar insights or recommendations regarding running Apache HTTPD (httpd) on RHEL 10? Are there any known issues, limitations, or

Re: RHEL 10 Compatibility for Apache Tomcat 8.x, 9.x, 10.x, and 11.x

2025-07-14 Thread Christopher Schultz
Bharath, On 7/14/25 9:17 AM, Cheruku, B.R. (Bharath) wrote: I would like to ask if anyone in the community has experience running Apache Tomcat versions 8.x, 9.x, 10.x, or 11.x on Red Hat Enterprise Linux 10 (RHEL 10). Are there any known issues, limitations, or recommendations for these

RHEL 10 Compatibility for Apache Tomcat 8.x, 9.x, 10.x, and 11.x

2025-07-14 Thread Cheruku, B.R. (Bharath)
Hello, I would like to ask if anyone in the community has experience running Apache Tomcat versions 8.x, 9.x, 10.x, or 11.x on Red Hat Enterprise Linux 10 (RHEL 10). Are there any known issues, limitations, or recommendations for these versions on RHEL 10? Additionally, if there is any

Re: [SECURITY] CVE-2025-52520 Apache Tomcat - DoS in multipart upload

2025-07-11 Thread Christopher Schultz
Mark, Oops, I'm sorry I didn't see this correction and just sent one of my own. :( -chris On 7/10/25 3:18 PM, Mark Thomas wrote: Correcting typo in fixed versions CVE-2025-52520 Apache Tomcat - DoS in multipart upload Severity: Low Vendor: The Apache Software Foundation Version

[SECURITY] CVE-2025-52520 Apache Tomcat - DoS in multipart upload [CORRECTION]

2025-07-11 Thread Christopher Schultz
CVE-2025-52520 Apache Tomcat - DoS in multipart upload Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.8 Apache Tomcat 10.1.0-M1 to 10.1.42 Apache Tomcat 9.0.0.M1 to 9.0.106 Description: For some unlikely configurations of multipart

Re: [EXTERNAL] [SECURITY] CVE-2025-52520 Apache Tomcat - DoS in multipart upload

2025-07-11 Thread Christopher Schultz
Joey, On 7/10/25 3:14 PM, Joey Cochran wrote: Is this accurate? Versions Affected: Apache Tomcat 10.1.0-M1 to 10.1.42 Mitigation: - Upgrade to Apache Tomcat 10.1.32 or later Nope, this should be "Upgrade to 10.1.43 or later". Thanks for noticing; we'll get this corrected an

[SECURITY] CVE-2025-53506 Apache Tomcat - DoS in HTP/2

2025-07-10 Thread Mark Thomas
Correcting typo in fixed versions CVE-2025-53506 Apache Tomcat - DoS in HTTP/2 Severity: High Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.8 Apache Tomcat 10.1.0-M1 to 10.1.42 Apache Tomcat 9.0.0.M1 to 9.0.106 Description: An uncontrolled resource

[SECURITY] CVE-2025-52520 Apache Tomcat - DoS in multipart upload

2025-07-10 Thread Mark Thomas
Correcting typo in fixed versions CVE-2025-52520 Apache Tomcat - DoS in multipart upload Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.8 Apache Tomcat 10.1.0-M1 to 10.1.42 Apache Tomcat 9.0.0.M1 to 9.0.106 Description: For some

Re: [EXTERNAL] [SECURITY] CVE-2025-52520 Apache Tomcat - DoS in multipart upload

2025-07-10 Thread Joey Cochran
Mark, Is this accurate? Versions Affected: Apache Tomcat 10.1.0-M1 to 10.1.42 Mitigation: - Upgrade to Apache Tomcat 10.1.32 or later Thanks! -Joey [cid:d114c52d-730d-4ed5-9b19-db4e930e1068] Joey Cochran Systems Administrator II Middleware Developer Information Technology

[SECURITY] CVE-2025-53506 Apache Tomcat - DoS in HTP/2

2025-07-10 Thread Mark Thomas
CVE-2025-53506 Apache Tomcat - DoS in HTTP/2 Severity: High Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.8 Apache Tomcat 10.1.0-M1 to 10.1.42 Apache Tomcat 9.0.0.M1 to 9.0.106 Description: An uncontrolled resource consumption vulnerability if an

[SECURITY] CVE-2025-52520 Apache Tomcat - DoS in multipart upload

2025-07-10 Thread Mark Thomas
CVE-2025-52520 Apache Tomcat - DoS in multipart upload Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.8 Apache Tomcat 10.1.0-M1 to 10.1.42 Apache Tomcat 9.0.0.M1 to 9.0.106 Description: For some unlikely configurations of multipart

[SECURITY] CVE-2025-52434 Apache Tomcat -APR/native Connector crash leading to DoS

2025-07-10 Thread Mark Thomas
CVE-2025-49125 Apache Tomcat - APR/Native Connector crash leading to DoS Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.105 Description: A race condition on connection close could trigger a JVM crash when using the APR/Native

[ANN] Apache Tomcat 9.0.107 available

2025-07-04 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.107. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.107 is a bugfix and

[ANN] Apache Tomcat 11.0.9 Available

2025-07-04 Thread Mark Thomas
The Apache Tomcat team announces the immediate availability of Apache Tomcat 11.0.9. Apache Tomcat 11 is an open source software implementation of the Jakarta Servlet, Jakarta Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations specifications

[ANN] Apache Tomcat 10.1.43 Available

2025-07-04 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 10.1.43. Apache Tomcat 10 is an open source software implementation of the Jakarta Servlet, Jakarta Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations specifications

Re: Restricting POST request size in Tomcat

2025-07-04 Thread Martin Konicsek
Hi Perplexity  wrote The maxPostSize attribute only applies to requests where Tomcat parses form data (e.g., application/x-www-form-urlencoded). For raw POST bodies (like application/json), maxPostSize may not be enforced by default in all Tomcat versions. If you need to restrict POST size

Restricting POST request size in Tomcat

2025-07-04 Thread S Abirami
Hi Team, We are looking into possibility of restricting the POST request size having content-type application/json in Tomcat. We want to ensure that attacker should not hit Rest API request directly with large request data. Expecting Tomcat application server level configuration should

Re: Apache Tomcat 10.1.42 Cache-Control header changed when added security-constraint with transport-guarantee CONFIDENTIAL

2025-07-04 Thread Mark Thomas
the NonLoginAuthenticator. The authenticator is the only place I see Tomcat setting: Cache-Control: private Mark - To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org For additional commands, e-mail: users-h

Re: Apache Tomcat 10.1.42 Cache-Control header changed when added security-constraint with transport-guarantee CONFIDENTIAL

2025-07-03 Thread Rolandas Karosas | Edrana Baltic
> Different value for securePagesWithPragma on the authenticator for the > two system being tested? No. authenticator is not used at all.

Re: Apache Tomcat 10.1.42 Cache-Control header changed when added security-constraint with transport-guarantee CONFIDENTIAL

2025-07-03 Thread Mark Thomas
On 03/07/2025 11:18, Rolandas Karosas | Edrana Baltic wrote: Hi, On Apache Tomcat 10.1.42 with configured SSL Connector web application with Spring, Spring Security returns the configured Default Spring Security Cache Control HTTP Response Headers Cache-Control: no-cache, no-store, max-age

Apache Tomcat 10.1.42 Cache-Control header changed when added security-constraint with transport-guarantee CONFIDENTIAL

2025-07-03 Thread Rolandas Karosas | Edrana Baltic
Hi, On Apache Tomcat 10.1.42 with configured SSL Connector web application with Spring, Spring Security returns the configured Default Spring Security Cache Control HTTP Response Headers Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: 0 But when I add to

Re: Monitoring Virtual Threads via JMX / MBeans in Tomcat

2025-06-26 Thread Rémy Maucherat
On Thu, Jun 26, 2025 at 6:23 AM Rose Mary P T wrote: > > Dear Rémy Maucherat, > > > > Thank you for your comments. I have another question: can we configure both > virtual threads and platform threads in the same Apache Tomcat server.xml > file? Specifically, is i

RE: Monitoring Virtual Threads via JMX / MBeans in Tomcat

2025-06-25 Thread Rose Mary P T
Dear Rémy Maucherat, Thank you for your comments. I have another question: can we configure both virtual threads and platform threads in the same Apache Tomcat server.xml file? Specifically, is it possible to set up one connector to support an application using virtual threads, and another

Re: Servlet 6.2 / Tomcat 12 - Welcome files

2025-06-25 Thread Christopher Schultz
Mark, On 6/25/25 9:58 AM, Mark Thomas wrote: On 25/06/2025 14:07, Mark Thomas wrote: I think I need to look at the rules for merging welcome resources. That might prompt some changes to the PR. At the moment, a is almost certain to match since it will likely be using extension mapping ma

Re: Servlet 6.2 / Tomcat 12 - Welcome files

2025-06-25 Thread Mark Thomas
On 25/06/2025 14:07, Mark Thomas wrote: I think I need to look at the rules for merging welcome resources. That might prompt some changes to the PR. At the moment, a is almost certain to match since it will likely be using extension mapping making any welcome resources that follow unneces

Re: Servlet 6.2 / Tomcat 12 - Welcome files

2025-06-25 Thread Mark Thomas
intention is that the index.jsp page should be used if present and index.do (which always maps to the servlet) used if it is not. However, a strict reading of the servlet spec requires that a 404 is returned if index.jsp is not present. Most containers have a workaround for this (Tomcat has

Re: Servlet 6.2 / Tomcat 12 - Welcome files

2025-06-25 Thread Mark Thomas
Tim, Thanks for looking at this. On 25/06/2025 13:55, Tim Funk wrote: This is a good cleanup. I one question for confirmation, let's say we have this config: index.html index.do index.htm With -- request = /foo/ -- AND file exists of = /foo/index.htm Since index.htm exists, we'd process as /f

Re: Servlet 6.2 / Tomcat 12 - Welcome files

2025-06-25 Thread Tim Funk
This is a good cleanup. I one question for confirmation, let's say we have this config: index.html index.do index.htm With -- request = /foo/ -- AND file exists of = /foo/index.htm Since index.htm exists, we'd process as /foo/index.htm despite it being "3rd" in the welcome file list since welcome

Re: Servlet 6.2 / Tomcat 12 - Welcome files

2025-06-25 Thread Rémy Maucherat
> The intention is that the index.jsp page should be used if present and > index.do (which always maps to the servlet) used if it is not. However, > a strict reading of the servlet spec requires that a 404 is returned if > index.jsp is not present. > > Most containers have a workaround for

Servlet 6.2 / Tomcat 12 - Welcome files

2025-06-25 Thread Mark Thomas
to the servlet) used if it is not. However, a strict reading of the servlet spec requires that a 404 is returned if index.jsp is not present. Most containers have a workaround for this (Tomcat has resourceOnlyServlets) but Servlet 6.2 intends to fix this properly by introducing a new element

Re: Need confirmation about CVE-2025-48988 impacting Tomcat 9.0.10x related to CVE-2025-48976.

2025-06-23 Thread Rémy Maucherat
case, do we still need to > update the Apache Tomcat to 9.0.106, 10.1.42 & 11.0.8 which has > CVE-2025-48988 fixed ? > Or is it not needed to update the Tomcat to these versions ? You need to upgrade Tomcat since it uses its own internal copy of fileupload to process the Servlet API mult

Need confirmation about CVE-2025-48988 impacting Tomcat 9.0.10x related to CVE-2025-48976.

2025-06-23 Thread Charpe, Anil
Hi, It is about the CVE-2025-48988 mentioned in the email subject. I have a question that- if we update the "Apache Commons FileUpload" jar to the version which fixes the CVE-2025-48976; in that case, do we still need to update the Apache Tomcat to 9.0.106, 10.1.42 & 11.0.8

Need confirmation about CVE-2025-48988 impacting Tomcat 9.0.10x related to CVE-2025-48976.

2025-06-23 Thread Charpe, Anil
Hi, It is about the CVE-2025-48988 mentioned in the email subject. I have a question that- if we update the "Apache Commons FileUpload" jar to the version which fixes the CVE-2025-48976; in that case, do we still need to update the Apache Tomcat to 9.0.106, 10.1.42 & 11.0.8

Re: Monitoring Virtual Threads via JMX / MBeans in Tomcat

2025-06-19 Thread Rémy Maucherat
eturned the wrong value for NIO. This is fixed. Let us know if you find other problems. Rémy > Looking forward to your response > > Regards, > Rose Mary > > From: Rose Mary P T > Date: Tuesday, 20 May 2025 at 4:07 PM > To: Tomcat Users List > Subject: [EXTERNAL] RE: Mo

Re: Tomcat GC overhead limit issue version-9.0.102.

2025-06-18 Thread Mark Thomas
On 18/06/2025 15:11, Raviteja Karanam wrote: TCS Confidential Not any more it isn't. You posted this question to a public mailing list. Hi Tomcat Team, We have recently upgraded the tomcat version from apache-tomcat-9.0.80 to apache-tomcat-9.0.102. After upgrade we are facing the

Tomcat GC overhead limit issue version-9.0.102.

2025-06-18 Thread Raviteja Karanam
TCS Confidential Hi Tomcat Team, We have recently upgraded the tomcat version from apache-tomcat-9.0.80 to apache-tomcat-9.0.102. After upgrade we are facing the issue java.lang.OutOfMemoryError:GC overhead limit execeeded. We have added the space from 4 GB to 8 GB but still issue exist

Re: Problem after tomcat upgrade

2025-06-17 Thread Stephen Booth
On 17/06/2025 17:29, Mark Thomas wrote: In short, you'll probably need to increase maxPartCount Thanks, thats fixed it.                             Stephen == |epcc| Dr Stephen P Booth Principal Architect

Re: Problem after tomcat upgrade

2025-06-17 Thread Mark Thomas
See https://bz.apache.org/bugzilla/show_bug.cgi?id=69710 In short, you'll probably need to increase maxPartCount Mark On 17/06/2025 16:45, Stephen Booth wrote: I just updated my production servers from 9.0.104 to 9.0.106 and this broke my registration form with the following exception. Stack

Problem after tomcat upgrade

2025-06-17 Thread Stephen Booth
I just updated my production servers from 9.0.104 to 9.0.106 and this broke my registration form with the following exception. Stack Trace: org.apache.tomcat.util.http.fileupload.impl.FileCountLimitExceededException: attachment at org.apache.tomcat.util.http.fileupload.FileUploadBase

RE: [SECURITY] CVE-2025-49125 Apache Tomcat - Security constraint bypass for pre/post-resources

2025-06-17 Thread Marco Krammer
[like] Marco Krammer reacted to your message: From: Mark Thomas Sent: Monday, June 16, 2025 1:59:33 PM To: Tomcat Users List Cc: annou...@apache.org ; annou...@tomcat.apache.org ; Tomcat Developers List Subject: [SECURITY] CVE-2025-49125 Apache Tomcat

[SECURITY] CVE-2025-49125 Apache Tomcat - Security constraint bypass for pre/post-resources

2025-06-16 Thread Mark Thomas
CVE-2025-49125 Apache Tomcat - Security constraint bypass for pre/post-resources Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.7 Apache Tomcat 10.1.0-M1 to 10.1.41 Apache Tomcat 9.0.0.M1 to 9.0.105 Description: When using

[SECURITY] CVE-2025-49124 Apache Tomcat - Side-loading via Tomcat installer for Windows

2025-06-16 Thread Mark Thomas
CVE-2025-49124 Apache Tomcat - Side-loading via Tomcat installer for Windows Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.7 Apache Tomcat 10.1.0 to 10.1.41 Apache Tomcat 9.0.23 to 9.0.105 Description: During installation, the Tomcat

[SECURITY] CVE-2025-48988 Apache Tomcat - DoS in multipart upload

2025-06-16 Thread Mark Thomas
CVE-2025-48988 Apache Tomcat - DoS in multipart upload Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.7 Apache Tomcat 10.1.0-M1 to 10.1.41 Apache Tomcat 9.0.0.M1 to 9.0.105 Description: Tomcat used the same limit for both request

[SECURITY] CVE-2025-48976 Apache Tomcat - DoS in Commons FileUpload

2025-06-16 Thread Mark Thomas
CVE-2025-48976 Apache Tomcat - DoS in Commons FileUpload Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.7 Apache Tomcat 10.1.0-M1 to 10.1.41 Apache Tomcat 9.0.0.M1 to 9.0.105 Description: Apache Commons FileUpload provided a hard

Re: [tomcat] Odd behavior enumerating http headers

2025-06-11 Thread Christopher Schultz
Alex, On 6/10/25 6:54 PM, Alex O'Ree wrote: Greetings I'm running tomcat v9.0.105 with a CXF based SOAP service (you know, the old school JAXWS services). Within that service, I had a need to retrieve a specific http header and i've been running into some inconsistent results. Th

[tomcat] Odd behavior enumerating http headers

2025-06-10 Thread Alex O'Ree
Greetings I'm running tomcat v9.0.105 with a CXF based SOAP service (you know, the old school JAXWS services). Within that service, I had a need to retrieve a specific http header and i've been running into some inconsistent results. The tomcat server is sitting behind a nginx pro

[ANN] Apache Tomcat 11.0.8 Available

2025-06-10 Thread Mark Thomas
The Apache Tomcat team announces the immediate availability of Apache Tomcat 11.0.8. Apache Tomcat 11 is an open source software implementation of the Jakarta Servlet, Jakarta Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations specifications

[ANN] Apache Tomcat 9.0.106 available

2025-06-10 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.106. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.106 is a bugfix and

[ANN] Apache Tomcat 10.1.42 Available

2025-06-09 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 10.1.42. Apache Tomcat 10 is an open source software implementation of the Jakarta Servlet, Jakarta Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations specifications

Re: Tomcat Performance from JMX data

2025-06-04 Thread Zdeněk Henek
w the ant tasks in the Tomcat documentation. Does anyone know of > something more ready to go out of the box, so to speak? > > > Regards > Mark Resh >

Re: Tomcat Performance from JMX data

2025-06-04 Thread Christopher Schultz
Mark, On 6/4/25 1:43 PM, Timothy Resh wrote: I have a production server with JMX enabled. However, we cannot install any additional software to do performance monitoring. We can, however, extract data from the MBeans and transfer it elsewhere for analysis. I saw the ant tasks in the Tomcat

Tomcat Performance from JMX data

2025-06-04 Thread Timothy Resh
ALCON, I have a production server with JMX enabled. However, we cannot install any additional software to do performance monitoring. We can, however, extract data from the MBeans and transfer it elsewhere for analysis. I saw the ant tasks in the Tomcat documentation. Does anyone know of

Re: adding new SSL certificate without restarting tomcat

2025-06-03 Thread Ivano Luberti
n the certificate is no concern. But if I add (or remove)  a new SSLHostConfig, tomcat needs to be restarted in order to take into account the new configuration. I would like to know if there is a way to configure tomcat so avoid restart. Even using a different way to configure tomcat o

Re: adding new SSL certificate without restarting tomcat

2025-06-03 Thread Mark Thomas
. But if I add (or remove)  a new SSLHostConfig,  tomcat needs to be restarted in order to take into account the new configuration. I would like to know if there is a way to configure tomcat so avoid restart. Even using a different way to configure tomcat outside of server.xml using a different cert

Re: adding new SSL certificate without restarting tomcat

2025-06-03 Thread Ivano Luberti
tificate renewal, reloadin the certificate is no concern. But if I add (or remove)  a new SSLHostConfig,  tomcat needs to be restarted in order to take into account the new configuration. I would like to know if there is a way to configure tomcat so avoid restart. Even using a different way to c

Re: adding new SSL certificate without restarting tomcat

2025-06-03 Thread Mark Thomas
like this certificateKeystoreFile="/etc/ssl/LetsEncrypt/host domain.it/host domain.it.pfx" certificateKeystorePassword="passwrod" certificateKeystoreType="PKCS12" /> after certificate renewal, reloadin the certificate is no concern. But if I add (or remove)  a new SSLHo

Re: adding new SSL certificate without restarting tomcat

2025-06-03 Thread Ivano Luberti
fter certificate renewal, reloadin the certificate is no concern. But if I add (or remove)  a new SSLHostConfig,  tomcat needs to be restarted in order to take into account the new configuration. I would like to know if there is a way to configure tomcat so avoid restart. Even using a differ

Re: [SECURITY] CVE-2025-46701 Apache Tomcat - CGI security constraint bypass

2025-05-30 Thread Justin Chen
Per original reports from Greg K, pathInfo is not the only weakness. From: Mark Thomas Sent: Friday, May 30, 2025 3:02 To: Tomcat Users List Cc: annou...@apache.org; annou...@tomcat.apache.org; Tomcat Developers List Subject: [SECURITY] CVE-2025-46701

[SECURITY] CVE-2025-46701 Apache Tomcat - CGI security constraint bypass

2025-05-29 Thread Mark Thomas
CVE-2025-46701 Apache Tomcat - CGI security constraint bypass Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.6 Apache Tomcat 10.1.0-M1 to 10.1.40 Apache Tomcat 9.0.0.M1 to 9.0.104 Description: When running on a case insensitive file

Re: adding new SSL certificate without restarting tomcat

2025-05-29 Thread Mark Thomas
ertificate is no concern. But if I add (or remove)  a new SSLHostConfig,  tomcat needs to be restarted in order to take into account the new configuration. I would like to know if there is a way to configure tomcat so avoid restart. Even using a different way to configure tomcat outside of serve

Re: adding new SSL certificate without restarting tomcat

2025-05-29 Thread Ivano Luberti
te renewal, reloadin the certificate is no concern. But if I add (or remove)  a new SSLHostConfig,  tomcat needs to be restarted in order to take into account the new configuration. I would like to know if there is a way to configure tomcat so avoid restart. Even using a different way to c

Re: adding new SSL certificate without restarting tomcat

2025-05-28 Thread Christopher Schultz
t.pfx" certificateKeystorePassword="passwrod" certificateKeystoreType="PKCS12" /> after certificate renewal, reloadin the certificate is no concern. But if I add (or remove)  a new SSLHostConfig,  tomcat needs to be restarted in order to take into account the new configuration. I

Re: adding new SSL certificate without restarting tomcat

2025-05-28 Thread Ivano Luberti
tificateKeystoreType="PKCS12" /> after certificate renewal, reloadin the certificate is no concern. But if I add (or remove)  a new SSLHostConfig,  tomcat needs to be  restarted in order to take into account the new configuration. I would like to know if there is a way to configu

Re: adding new SSL certificate without restarting tomcat

2025-05-28 Thread Michael Osipov
On 2025/05/27 20:11:25 Ivano Luberti wrote: > Hi all, is there a way to configure tomcat in order to avoid restart > when I change the list of ssl certificates? > > I know and I do it, how to reload existing certificates, but I'm > searching a qay to avoid reloading wh

Re: adding new SSL certificate without restarting tomcat

2025-05-28 Thread Mark Thomas
On 27/05/2025 21:11, Ivano Luberti wrote: Hi all, is there a way to configure tomcat in order to avoid restart when I change the list of ssl certificates? Which list of certificates? There are several. Exactly what are you changing? Are you adding a cert to a keystore, adding a PEM file to a

Re: Tomcat 9.0.x support Java 17 ?

2025-05-28 Thread Zdeněk Henek
Hi, here is all you need https://tomcat.apache.org/whichversion.html We run Tomcat 9 even with OpenJDK 21. Regards, Zdenek Henek On Wed, May 28, 2025 at 5:04 AM dineshk wrote: > Hi Team, > Could anybody clarify on if we could use Java 17 with Java EE specs with > tom

Tomcat 9.0.x support Java 17 ?

2025-05-27 Thread dineshk
Hi Team,  Could anybody clarify on if we could use Java 17 with Java EE specs with tomcat 9.0.x ? RegardsDinesh Sent from Yahoo Mail for iPhone

adding new SSL certificate without restarting tomcat

2025-05-27 Thread Ivano Luberti
Hi all, is there a way to configure tomcat in order to avoid restart when I change the list of ssl certificates? I know and I do it, how to reload existing certificates, but I'm searching a qay to avoid reloading when I add or remove a certificate. I'm using Tomcat 9 , but l

Re: Apache Tomcat 9 SAML Setup With Active Directory

2025-05-22 Thread Christopher Schultz
William, On 4/9/25 11:09 AM, William Crowell wrote: Is there any current up-to-date documentation on how to setup Apache Tomcat 9 with SAML and Active Directory that is not AI generated? I know you can do Keycloak IdP with Tomcat, but I was trying to avoid setting up an identity provider. I

Re: Tomcat 9, ClassCast exception

2025-05-21 Thread Mark Thomas
On 21/05/2025 13:44, Zdeněk Henek wrote: Hello, I am getting these errors in one of our systems: java.lang.ClassCastException: class com.sun.mail.handlers.text_html cannot be cast to class javax.activation.DataContentHandler (com.sun.mail.handlers.text_html is in unnamed module of loader org.ap

Re: Tomcat 9, ClassCast exception

2025-05-21 Thread Zdeněk Henek
/activation-1.1.jar [558992.846s][info][class,load] javax.activation.DataContentHandler source: file:/mnt/app/tomcat/webapps/app4/WEB-INF/lib/activation-1.1.jar (0) $ grep com.sun.mail.handlers.text_html classloaded.log [5436.558s][info][class

Tomcat 9, ClassCast exception

2025-05-21 Thread Zdeněk Henek
Tomcat 9.0.102, OpenJDK Runtime Environment Temurin-21.0.6+7 (build 21.0.6+7-LTS), RHEL 9.5 Linux The functionality has a number of threads in the thread pool and only one of the threads is causing this issue. Other threads are working as expected. I am aware of duplicated jar files (even the same

RE: Monitoring Virtual Threads via JMX / MBeans in Tomcat

2025-05-20 Thread Rose Mary P T
From: Rose Mary P T Date: Tuesday, 20 May 2025 at 4:07 PM To: Tomcat Users List Subject: [EXTERNAL] RE: Monitoring Virtual Threads via JMX / MBeans in Tomcat HI Mark, Just a gentle reminder regarding my previous message. I’m following up to see if there’s any update on this. Please let me know

RE: Monitoring Virtual Threads via JMX / MBeans in Tomcat

2025-05-20 Thread Rose Mary P T
2025 at 7:08 PM To: Tomcat Users List , ma...@apache.org Subject: [EXTERNAL] RE: Monitoring Virtual Threads via JMX / MBeans in Tomcat Dear Tomcat Users/Mark, I was finally able to retrieve the thread name from the workerThreadName attribute in RequestProcessor.tomcatExecutor for a request. In order

Re: generating local maven archetypes from tomcat sources

2025-05-13 Thread Ernesto Reinaldo Barreiro
Found https://github.com/apache/tomcat/blob/main/res/maven/README.txt On Tue, May 13, 2025 at 1:28 PM Ernesto Reinaldo Barreiro < reier...@gmail.com> wrote: > Hi, > > I cloned/forked tomcat sources and the build is ANT based. Question. I > managed to generate a build but I wan

generating local maven archetypes from tomcat sources

2025-05-13 Thread Ernesto Reinaldo Barreiro
Hi, I cloned/forked tomcat sources and the build is ANT based. Question. I managed to generate a build but I want to install in my local maven repositories a distribution of the jar files with this "SNAPSHOT" version. Is there some "ready" ant task I can use to do so? -

Re: multipart and Apache Tomcat 11

2025-05-13 Thread Ernesto Reinaldo Barreiro
0-SNAPSHOT. And we will be able to use tomcat 11... as soon as Wicket 10.6.0 is released... But while doing this work I realized Tomcat already has an upload progress listening machinery. What I didn't find is a way to hack into the coyote Request and plug in a custom listener. Thus, I just cre

Re: Tomcat 10.1 Upgrade & Uber JAR Error

2025-05-12 Thread Tim N
The issue occurred again in Tomcat v10.1.40 but is fixed again in Tomcat v10.1.41 On Thu, Apr 3, 2025 at 7:52 PM Mark Thomas wrote: > On 03/04/2025 05:34, Tim N wrote: > > That should have been > >> Looks like this last worked Tomcat v10.1.20 and first failed v10.1.23 > &

Re: [ANN] Apache Tomcat 9.0.105 available

2025-05-12 Thread Robert F Hall
> On May 12, 2025, at 2:01 PM, Rémy Maucherat wrote: > > The Apache Tomcat team announces the immediate availability of Apache > Tomcat 9.0.105. > > Apache Tomcat 9 is an open source software implementation of the Java > Servlet, JavaServer Pages, Java Unified Expr

[ANN] Apache Tomcat 9.0.105 available

2025-05-12 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.105. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.104 is a bugfix and

Re: multipart and Apache Tomcat 11

2025-05-06 Thread Ernesto Reinaldo Barreiro
Hi, It seems this happens also with tomcat 10.1.x under certain circumstances. I have create https://github.com/reiern70/file-upload-broken to illustrate the problem. Hope this helps reproduce the problem. If I can further assist getting this "fixed" please let me know On Fri, May 2,

Re: Content type unknown after upgrading Tomcat 10.1.39 => 10.1.40

2025-05-05 Thread Christopher Schultz
Thorsten, On 5/2/25 2:49 PM, Thorsten Heit wrote: please excuse the long delay in answering (unplanned holidays...) Tomcat is never going to figure out what MIME type should be used for a request like "/my/servlet/app?version=!!1.22.32-4-g8a3c060!!" So I think Mark is probably r

Re: multipart and Apache Tomcat 11

2025-05-02 Thread Ernesto Reinaldo Barreiro
; > application works as expected with the latest Tomcat 10.1.40. But our > > application does not work with Tomcat 11.0.6 because file upload > (multipart > > processing is broken). > > > > Apache wicket 10.x uses fileupload2.jakarta.servlet5 thus I create a > br

Re: Content type unknown after upgrading Tomcat 10.1.39 => 10.1.40

2025-05-02 Thread Thorsten Heit
Hi Chris, please excuse the long delay in answering (unplanned holidays...) Tomcat is never going to figure out what MIME type should be used for a request like "/my/servlet/app?version=!!1.22.32-4-g8a3c060!!" So I think Mark is probably right (well, he's right like 99.999% o

Re: multipart and Apache Tomcat 11

2025-05-02 Thread Christopher Schultz
Ernesto, On 5/1/25 8:51 PM, Ernesto Reinaldo Barreiro wrote: We have an Apache Wicket application that I just ported to wicket 10. The application works as expected with the latest Tomcat 10.1.40. But our application does not work with Tomcat 11.0.6 because file upload (multipart processing is

Re: Help with Cluster Setup on Tomcat 9

2025-05-02 Thread Christopher Schultz
short window from when tomcat creates a new session and when it is persisted to db which under heavy loads duplicates can be created. Each node generates a session identifier for itself, and the (default) session id space is quite large (2^128 bits or 340282366920938463463374607431768211456

Re: [EXT]multipart and Apache Tomcat 11

2025-05-02 Thread Ernesto Reinaldo Barreiro
Hi, Thank you very much for your email. My answers inlined. On Fri, May 2, 2025 at 6:54 AM Rick Noel wrote: > We had the same issue when going to Tomcat 11. > > You need to make two changes. > 1) get the request params passed in via. > jakarta.servlet.http.P

RE: [EXT]multipart and Apache Tomcat 11

2025-05-02 Thread Rick Noel
We had the same issue when going to Tomcat 11. You need to make two changes. 1) get the request params passed in via. jakarta.servlet.http.Part Like so. import jakarta.servlet.http.Part; Part fileUpload = request.getPart("param-name"); if(null !=

Re: Help with Cluster Setup on Tomcat 9

2025-05-01 Thread Zoran Avtarovski
Thanks Chris, I appreciate you input. In answer to your questions the primary issue we are experiencing is that on occasions (once a month or two) we will get two users on different nodes with the same session id. We suspect this could be because there is a short window from when tomcat

multipart and Apache Tomcat 11

2025-05-01 Thread Ernesto Reinaldo Barreiro
Hi, We have an Apache Wicket application that I just ported to wicket 10. The application works as expected with the latest Tomcat 10.1.40. But our application does not work with Tomcat 11.0.6 because file upload (multipart processing is broken). Apache wicket 10.x uses fileupload2

Re: When was the first stable GA release of Apache Tomcat 11.0.x?

2025-04-30 Thread Mark Thomas
Minor nit: Tomcat also supports: Jakarta Annotations Jakarta Debugging Support for Other Languages but we don't list then on the spec age. We probably should. Mark On 29/04/2025 15:36, William Crowell wrote: Chris, Beautiful answer and exactly what I was looking for. Thank you. Re

Re: When was the first stable GA release of Apache Tomcat 11.0.x?

2025-04-29 Thread William Crowell
Chris, Beautiful answer and exactly what I was looking for. Thank you. Regards, William Crowell From: Christopher Schultz Date: Tuesday, April 29, 2025 at 10:32 AM To: Tomcat Users List , William Crowell Subject: Re: When was the first stable GA release of Apache Tomcat 11.0.x? William

Re: When was the first stable GA release of Apache Tomcat 11.0.x?

2025-04-29 Thread Christopher Schultz
William, On 4/29/25 7:04 AM, William Crowell wrote: Just for my clarification: When was the first stable GA release of Apache Tomcat 11.0.x? I believe it was October 9th, 2024, but I did see the Jakarta EE Platform Web Profile 11 was released on March 30th, 2025: https://projects.eclipse.org

When was the first stable GA release of Apache Tomcat 11.0.x?

2025-04-29 Thread William Crowell
Good morning, Just for my clarification: When was the first stable GA release of Apache Tomcat 11.0.x? I believe it was October 9th, 2024, but I did see the Jakarta EE Platform Web Profile 11 was released on March 30th, 2025: https://projects.eclipse.org/projects/ee4j.jakartaee-platform

  1   2   3   4   5   6   7   8   9   10   >