Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2026:20926-1 — tomcat11 (CVE-2025-66614 +2 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for tomcat11

This update for tomcat11 fixes the following issues:

Update to Tomcat 11.0.18:

  • CVE-2025-66614: client certificate verification bypass due to virtual host mapping (bsc#1258371).
  • CVE-2026-24733: improper input validation on HTTP/0.9 requests (bsc#1258385).
  • CVE-2026-24734: certificate revocation bypass due to incomplete OCSP verification checks (bsc#1258387).

Changelog:

+ Fix: 69932: Fix request end access log pattern regression, which would log

the start time of the request instead. (remm)

+ Fix: 69623: Additional fix for the long standing regression that meant

that calls to ClassLoader.getResource().getContent() failed when made from

within a web application with resource caching enabled if the target

resource was packaged in a JAR file. (markt)

+ Fix: Pull request #923: Avoid adding multiple CSRF tokens to a URL in the

CsrfPreventionFilter. (schultz)

+ Fix: 69918: Ensure request parameters are correctly parsed for HTTP/2

requests when the content-length header is not set. (dsoumis)

+ Update: Enable minimum and recommended Tomcat Native versions to be set

separately for Tomcat Native 1.x and 2.x. Update the minimum and

recommended versions for Tomcat Native 1.x to 1.3.4. Update the minimum

and recommended versions for Tomcat Native 2.x to 2.0.12. (markt)

+ Add: Add a new ssoReauthenticationMode to the Tomcat provided

Authenticators that provides a per Authenticator override of the SSO Valve

requireReauthentication attribute. (markt)

+ Fix: Ensure URL encoding errors in the Rewrite Valve trigger an exception

rather than silently using a replacement character. (markt)

+ Fix: 69871: Increase log level to INFO for missing configuration for the

rewrite valve. (remm)

+ Fix: Add log warnings for additional Host appBase suspicious values.

(remm)

+ Fix: Remove hard dependency on tomcat-jni.jar for catalina.jar.

org.apache.catalina.Connector no longer requires

org.apache.tomcat.jni.AprStatus to be present. (markt)

+ Add: Add the ability to use a custom function to generate the client

identifier in the CrawlerSessionManagerValve. This is only available

programmatically. Pull request #902 by Brian Matzon. (markt)

+ Fix: Change the SSO reauthentication behaviour for SPNEGO authentication

so that a normal SPNEGO authentication is performed if the SSL Valve is

configured with reauthentication enabled. This is so that the delegated

credentials will be available to the web application. (markt)

+ Fix: When generating the class path in the Loader, re-order the check on

individual class path components to avoid a potential

NullPointerException. Identified by Coverity Scan. (markt)

+ Fix: Fix SSL socket factory configuration in the JNDI realm. Based on pull

request #915 by Joshua Rogers. (remm)

+ Update: Add an attribute, digestInRfc3112Order, to

MessageDigestCredentialHandler to control the order in which the

credential and salt are digested. By default, the current, non-RFC 3112

compliant, order of salt then credential will be used. This default will

change in Tomcat 12 to the RFC 3112 compliant order of credential then

salt. (markt)

  • Cluster

+ Add: 62814: Document that human-readable names may be used for

mapSendOptions and align documentation with channelSendOptions. Based on

pull request #929 by archan0621. (markt)

  • Clustering

+ Fix: Correct a regression introduced in 11.0.11 that broke some clustering

configurations. (markt)

  • Coyote

+ Fix: 69936: Fix bug in previous fix for Tomcat Native crashes on shutdown

that triggered a significant memory leak. Patch provided by Wes. (markt)

+ Fix: Prevent concurrent release of OpenSSLEngine resources and the

termination of the Tomcat Native library as it can cause crashes during

Tomcat shutdown. (markt)

+ Fix: Improve warnings when setting ciphers lists in the FFM code,

mirroring the tomcat-native changes. (remm)

+ Fix: 69910: Dereference TLS objects right after closing a socket to

improve memory efficiency. (remm)

+ Fix: Relax the JSSE vs OpenSSL configuration style checks on SSLHostConfig

to reflect the existing implementation that allows one configuration style

to be used for the trust attributes and a different style for all the

other attributes. (markt)

+ Fix: Better warning message when OpenSSLConf configuration elements are

used with a JSSE TLS implementation. (markt)

+ Fix: When using OpenSSL via FFM, don't log a warning about missing CA

certificates unless CA certificates were configured and the configuration

failed. (markt)

+ Add: For configuration consistency between OpenSSL and JSSE TLS

implementations, TLSv1.3 cipher suites included in the ciphers attribute

of an SSLHostConfig are now always ignored (previously they would be

ignored with OpenSSL implementations and used with JSSE implementations)

and a warning is logged that the cipher suite has been ignored. (markt)

+ Add: Add the ciphersuite attribute to SSLHostConfig to configure the

TLSv1.3 cipher su

Affected software

SUSE-SU-2026:20926-1 is recorded against 1 package.

  • tomcat11 (fixed in 11.0.18-160000.1.1)

Timeline and source

Published on 24 March 2026 and last revised on 2 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-03-24
Updated 2026-08-20
Modified 2026-04-02
Fix URL N/A

Affected Packages

Software From version Fixed in
tomcat11 11.0.18-160000.1.1

Free Vulnerability Check

Is your site affected by SUSE-SU-2026:20926-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:20926-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.