users
Thread
Date
Earlier messages
Messages by Thread
[ANN] Apache Tomcat Migration tool for Jakarta EE 1.0.13
Mark Thomas
Certificate lifetime changes to 90 days on 1/1/2027
Darryl Baker
Clarification on Mitigation for Security Vulnerabilities Fixed in Tomcat 9.0.122
Thiru
Re: Clarification on Mitigation for Security Vulnerabilities Fixed in Tomcat 9.0.122
Sebastian Trost via users
Re: Clarification on Mitigation for Security Vulnerabilities Fixed in Tomcat 9.0.122
Thiru
Re: Clarification on Mitigation for Security Vulnerabilities Fixed in Tomcat 9.0.122
Thiru
Re: Clarification on Mitigation for Security Vulnerabilities Fixed in Tomcat 9.0.122
Mark Thomas
Re: Clarification on Mitigation for Security Vulnerabilities Fixed in Tomcat 9.0.122
Thiru
Bundling default web apps
Amit Pande via users
Re: Bundling default web apps
Christopher Schultz
Re: Bundling default web apps
Olaf Kock
Re: Bundling default web apps
James H. H. Lampert via users
Re: Bundling default web apps
Olaf Kock
Re: Bundling default web apps
Simon Matter via users
Re: Bundling default web apps
Olaf Kock
Re: Bundling default web apps
Peter Kreuser via users
Re: Bundling default web apps
James H. H. Lampert via users
Re: Bundling default web apps
Amit Pande via users
[SECURITY] CVE-2026-77762 Apache Tomcat - Stale HPACK emitter injects trailers into recycled pooled Request
Mark Thomas
[UPDATE][SECURITY] CVE-2026-77762 Apache Tomcat - Stale HPACK emitter injects trailers into recycled pooled Request
Mark Thomas via users
[UPDATE][SECURITY] CVE-2026-77762 Apache Tomcat - Stale HPACK emitter injects trailers into recycled pooled Request
Mark Thomas
[SECURITY] CVE-2026-86247 Apache Tomcat Native - Client certificate requirements can be down-graded
Mark Thomas
[SECURITY] CVE-2026-86246 Apache Tomcat Native - Insecure OpenSSL options enabled
Mark Thomas
[SECURITY] CVE-2026-86243 Apache Tomcat Native - DoS via TLS handshake
Mark Thomas
[SECURITY] CVE-2026-78437 Apache Tomcat - HTTP/2 DoS via malformed request
Mark Thomas
[UPDATE][SECURITY] CVE-2026-78437 Apache Tomcat - HTTP/2 DoS via malformed request
Mark Thomas via users
[UPDATE][SECURITY] CVE-2026-78437 Apache Tomcat - HTTP/2 DoS via malformed request
Mark Thomas
[SECURITY] CVE-2026-87022 Apache Tomcat - WebSocket message smuggling with per-message-deflate
Mark Thomas
[UPDATE][SECURITY] CVE-2026-87022 Apache Tomcat - WebSocket message smuggling with per-message-deflate
Mark Thomas
[UPDATE][SECURITY] CVE-2026-87022 Apache Tomcat - WebSocket message smuggling with per-message-deflate
Mark Thomas via users
[SECURITY] CVE-2026-86350 Apache Tomcat - Regression in fix for CVE-2026-41293 can trigger request header mix-up
Mark Thomas
[UPDATE][SECURITY] CVE-2026-86350 Apache Tomcat - Regression in fix for CVE-2026-41293 can trigger request header mix-up
Mark Thomas
[UPDATE][SECURITY] CVE-2026-86350 Apache Tomcat - Regression in fix for CVE-2026-41293 can trigger request header mix-up
Mark Thomas via users
[SECURITY] CVE-2026-79677 Apache Tomcat - WebSocket DoS due to lost asynchronous write timeout
Mark Thomas
[UPDATE][SECURITY] CVE-2026-79677 Apache Tomcat - WebSocket DoS due to lost asynchronous write timeout
Mark Thomas via users
[UPDATE][SECURITY] CVE-2026-79677 Apache Tomcat - WebSocket DoS due to lost asynchronous write timeout
Mark Thomas
[SECURITY] CVE-2026-86248 Apache Tomcat - Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas
[UPDATE][SECURITY] CVE-2026-86248 Apache Tomcat - Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas via users
[UPDATE][SECURITY] CVE-2026-86248 Apache Tomcat - Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas
[SECURITY] CVE-2026-78383 Apache Tomcat - AJP DoS via missing request body
Mark Thomas
[UPDATE][SECURITY] CVE-2026-78383 Apache Tomcat - AJP DoS via missing request body
Mark Thomas
[UPDATE][SECURITY] CVE-2026-78383 Apache Tomcat - AJP DoS via missing request body
Mark Thomas via users
[SECURITY] CVE-2026-77791 Apache Tomcat - DoS via busy wait during WebSocket close
Mark Thomas
[UPDATE][SECURITY] CVE-2026-77791 Apache Tomcat - DoS via busy wait during WebSocket close
Mark Thomas via users
[UPDATE][SECURITY] CVE-2026-77791 Apache Tomcat - DoS via busy wait during WebSocket close
Mark Thomas
[SECURITY] CVE-2026-77756 Apache Tomcat - Transfer-Encoding honored for HTTP/1.0 requests
Mark Thomas
[UPDATE][SECURITY] CVE-2026-77756 Apache Tomcat - Transfer-Encoding honored for HTTP/1.0 requests
Mark Thomas
[UPDATE][SECURITY] CVE-2026-77756 Apache Tomcat - Transfer-Encoding honored for HTTP/1.0 requests
Mark Thomas via users
[SECURITY] CVE-2026-75973 Apache Tomcat - Cross-context authentication mix-up with Jakarta Authentication configured
Mark Thomas
[UPDATE][SECURITY] CVE-2026-75973 Apache Tomcat - Cross-context authentication mix-up with Jakarta Authentication configured
Mark Thomas via users
[UPDATE][SECURITY] CVE-2026-75973 Apache Tomcat - Cross-context authentication mix-up with Jakarta Authentication configured
Mark Thomas
[SECURITY] CVE-2026-76183 Apache Tomcat - Bypass of security constraints for WebSocket endpoints
Mark Thomas
[UPDATE][SECURITY] CVE-2026-76183 Apache Tomcat - Bypass of security constraints for WebSocket endpoints
Mark Thomas
[UPDATE][SECURITY] CVE-2026-76183 Apache Tomcat - Bypass of security constraints for WebSocket endpoints
Mark Thomas via users
[SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
Mark Thomas
Re: [SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
James H. H. Lampert via users
Re: [SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
Mark Thomas
Re: [SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
James H. H. Lampert via users
[UPDATE][SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
Mark Thomas
Tomcat 11: HttpParser.readHostIPv4 always throws ArrayIndexOutOfBoundsException during IPv4 host parsing
Chunhui Liu
Re: Tomcat 11: HttpParser.readHostIPv4 always throws ArrayIndexOutOfBoundsException during IPv4 host parsing
Mark Thomas
Re: Tomcat 11: HttpParser.readHostIPv4 always throws ArrayIndexOutOfBoundsException during IPv4 host parsing
Chunhui Liu
Re: Tomcat 11: HttpParser.readHostIPv4 always throws ArrayIndexOutOfBoundsException during IPv4 host parsing
Mark Thomas
Re: Tomcat 11: HttpParser.readHostIPv4 always throws ArrayIndexOutOfBoundsException during IPv4 host parsing
Chunhui Liu
Problems after OCSP changes in Tomcat Native 2.0.16
logo
Re: Problems after OCSP changes in Tomcat Native 2.0.16
Stefan Mayr
Re: Problems after OCSP changes in Tomcat Native 2.0.16
Mark Thomas
Re: Problems after OCSP changes in Tomcat Native 2.0.16
logo
Re: Problems after OCSP changes in Tomcat Native 2.0.16
Mark Thomas
Re: Problems after OCSP changes in Tomcat Native 2.0.16
logo
Re: Problems after OCSP changes in Tomcat Native 2.0.16
Mark Thomas
Re: Problems after OCSP changes in Tomcat Native 2.0.16
Peter Kreuser
Re: Problems after OCSP changes in Tomcat Native 2.0.16
Mark Thomas
Re: Problems after OCSP changes in Tomcat Native 2.0.16
logo.kreuser.name via users
Re: Problems after OCSP changes in Tomcat Native 2.0.16
Peter Kreuser
Questions regarding Mail Security SPF/DMARC and tomcat group emails
logo
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
Mark Thomas
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
logo
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
logo
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
logo
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
Torsten Krah
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
Mark Thomas
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
Piotr P. Karwasz
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
Peter Kreuser
Re: Questions regarding Mail Security SPF/DMARC and tomcat group emails
Peter Kreuser via users
[ANN] Apache Tomcat 9.0.122 available
Rémy Maucherat
Re: [ANN] Apache Tomcat 9.0.122 available
Andrei Ivanov
Re: [ANN] Apache Tomcat 9.0.122 available
Mark Thomas
[ANN] Apache Tomcat 11.0.26 Available
Mark Thomas
Re: [ANN] Apache Tomcat 11.0.26 Available - libtcnative location
Evan Rempel via users
Re: [ANN] Apache Tomcat 11.0.26 Available - libtcnative location
Mark Thomas
[ANN] Apache Tomcat 10.1.60 Available
Christopher Schultz
[ANN] Apache Tomcat Native 1.3.9 released
Mark Thomas
Re: [ANN] Apache Tomcat Native 1.3.9 released
Evan Rempel via users
Re: [ANN] Apache Tomcat Native 1.3.9 released
Mark Thomas
Re: [ANN] Apache Tomcat Native 1.3.9 released
Evan Rempel via users
Re: [ANN] Apache Tomcat Native 1.3.9 released
Noelette Stout
Re: [ANN] Apache Tomcat Native 1.3.9 released
Evan Rempel via users
Re: [ANN] Apache Tomcat Native 1.3.9 released
logo
[ANN] Apache Tomcat Native 2.0.16 released
Mark Thomas
Re: [ANN] Apache Tomcat Native 2.0.16 released
Simon Matter
Re: [ANN] Apache Tomcat Native 2.0.16 released
logo
Re: [ANN] Apache Tomcat Native 2.0.16 released
Mark Thomas
Re: [ANN] Apache Tomcat Native 2.0.16 released
Simon Matter
Re: [ANN] Apache Tomcat Native 2.0.16 released
Mark Thomas
Tomcat Severity Ratings verus CVSS
Darryl Baker
Re: Tomcat Severity Ratings verus CVSS
[email protected]
Re: Tomcat Severity Ratings verus CVSS
Christopher Schultz
Re: Tomcat Severity Ratings verus CVSS
Darryl Baker
[SECURITY] CVE-2026-73180 Apache Tomcat - Authenticated WebSocket session survives end of HTTP session
Mark Thomas
[SECURITY] CVE-2026-68763 Apache Tomcat - DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
Mark Thomas
[SECURITY] CVE-2026-68569 Apache Tomcat - Principal lookup can fail open in some cases
Mark Thomas
[SECURITY] CVE-2026-68525 Apache Tomcat - Redirect after FORM authentication may bypass method specific constraints
Mark Thomas
[SECURITY] CVE-2026-66422 Apache Tomcat - Servlet role references can bypass declarative role constraints
Mark Thomas
[SECURITY] CVE-2026-65927 Apache Tomcat - RewriteValve [N] restarts at the second rule and may bypass access control
Mark Thomas
[SECURITY] CVE-2026-65905 Apache Tomcat - Limited replay attack possible with DIGEST authentication
Mark Thomas
[SECURITY] CVE-2026-65637 Apache Tomcat - HTTP/2 no-authority bypass of strict SNI validation
Mark Thomas
[SECURITY] CVE-2026-65183 Apache Tomcat - TOCTOU when setting specific permissions for Unix Domain Sockets
Mark Thomas
[SECURITY] CVE-2026-65182 Apache Tomcat - Security constraint bypass
Mark Thomas
Support for gMSA
Lambert, Dominique via users
Re: Support for gMSA
Mark Thomas
RE: Support for gMSA
Lambert, Dominique via users
Fwd: Version 10.1.57 / 10.1.59
Brian Proffitt
AW: Version 10.1.57 / 10.1.59
Thomas Hoffmann (Speed4Trade GmbH) via users
Re: AW: Version 10.1.57 / 10.1.59
Mark Thomas
Update for new versions
Venkumahanti Praveen
Re: Update for new versions
Mark Thomas
Tomcat Embed Core 10.1.58
Raghu Dev
Re: Tomcat Embed Core 10.1.58
Chuck Caldarale
Re: Tomcat Embed Core 10.1.58
Eric Fetzer
Re: Tomcat Embed Core 10.1.58
Mark Thomas
Re: Tomcat Embed Core 10.1.58
Eric Fetzer
Re: Tomcat Embed Core 10.1.58
Christopher Schultz
Re: Tomcat Embed Core 10.1.58
Roger Marquis
Re: Tomcat Embed Core 10.1.58
Mark Thomas
[ANN] Apache Tomcat 9.0.121 available
Rémy Maucherat
[ANN] Apache Tomcat 11.0.25 Available
Mark Thomas
Status and timeline inquiry for Apache Tomcat 11.0.25 release
Terry ST SY/DPO
Re: Status and timeline inquiry for Apache Tomcat 11.0.25 release
Chuck Caldarale
Tomcat 11.0.25 Release Timeline Inquiry
joao-paulo.martins-prestataire.ca-ps.com via users
Re: Tomcat 11.0.25 Release Timeline Inquiry
Sebastian Trost via users
Re: Tomcat 11.0.25 Release Timeline Inquiry
Jo�o Paulo Sim�es Martins via users
Re: Tomcat 11.0.25 Release Timeline Inquiry
Mark Thomas
Re: Tomcat 11.0.25 Release Timeline Inquiry
Christopher Schultz
Session clustering between tomcat versions.
Stephen Booth
Re: Session clustering between tomcat versions.
Mark Thomas
Regarding apache-tomcat 10.1.58 version
Roshan Patil
AW: Regarding apache-tomcat 10.1.58 version
Döscher, Andreas (ESI) via users
Re: AW: Regarding apache-tomcat 10.1.58 version
Roshan Patil
Re: Regarding apache-tomcat 10.1.58 version
Rob Sargent
Re: AW: Regarding apache-tomcat 10.1.58 version
Mark Thomas
Regarding apache-tomcat 10.1.58 version
Roshan Patil
Re: Regarding apache-tomcat 10.1.58 version
Mark Thomas
Community over Code Sydney 2026
Mark Thomas
Re: Community over Code Sydney 2026
Mark Thomas
Community over Code Glasgow 2026
Mark Thomas
[SECURITY] CVE-2026-66299 Apache Tomcat - DoS via WebSocket chat example
Mark Thomas
London - Tues 28 July - evening
Mark Thomas
Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
LAURIA Giuseppe via users
Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Tim Funk
AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
LAURIA Giuseppe via users
Re: AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Sebastian Trost via users
Re: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Peter Kreuser
Re: AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Mark Thomas
Re: AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Rémy Maucherat
AW: [EXTERNAL] Re: AW: Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
LAURIA Giuseppe via users
Re: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Zdeněk Henek
Re: AW: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Christopher Schultz
Tomcat Jobs?
Jon McAlexander
Re: Tomcat Jobs?
Sebastian Trost via users
Re: Tomcat Jobs?
Jon McAlexander
Re: Tomcat Jobs?
Sebastian Trost via users
Possible missing CVE commits in 9.0.120, 10.1.57 and 11.0.24 release builds
Thomas Williams
Re: Possible missing CVE commits in 9.0.120, 10.1.57 and 11.0.24 release builds
Mark Thomas
Apache Tomcat 9.1.x release timeframe
Lisa Sayre
Re: Apache Tomcat 9.1.x release timeframe
Mark Thomas
Re: Apache Tomcat 9.1.x release timeframe
david w
RE: Apache Tomcat 9.1.x release timeframe
Lisa Sayre
Re: Apache Tomcat 9.1.x release timeframe
Sebastian Trost via users
RE: Apache Tomcat 9.1.x release timeframe
Eddie Rowe via users
Re: Apache Tomcat 9.1.x release timeframe
Mark Thomas
RE: Apache Tomcat 9.1.x release timeframe
Lisa Sayre
Re: Apache Tomcat 9.1.x release timeframe
Mark Thomas
RE: Apache Tomcat 9.1.x release timeframe
Lisa Sayre
Re: Apache Tomcat 9.1.x release timeframe
Christopher Schultz
Re: Apache Tomcat 9.1.x release timeframe
Sebastian Trost via users
Re: [OT] Apache Tomcat 9.1.x release timeframe
Christopher Schultz
Re: Apache Tomcat 9.1.x release timeframe
Christopher Schultz
Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Olaf Kock
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
Christopher Schultz
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Anushka sur
Re: Tomcat host header redirect issue
Mark Thomas
Re: Tomcat host header redirect issue
GUSTAVO AVITABILE
Earlier messages