Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-41293

Опубликовано: 12 мая 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 9.8

Описание

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

РелизСтатусПримечание
devel

not-affected

10.1.55-1ubuntu1
esm-apps/noble

released

10.1.16-1ubuntu0.1~esm4
esm-apps/resolute

released

10.1.40-1ubuntu1.26.04.1
jammy

DNE

noble

needed

questing

released

10.1.40-1ubuntu1.25.10.1
resolute

released

10.1.40-1ubuntu1.26.04.1
upstream

needed

Показывать по

РелизСтатусПримечание
devel

not-affected

11.0.22
esm-apps/resolute

released

11.0.18-1ubuntu0.1~esm1
jammy

DNE

noble

DNE

questing

ignored

end of life, was needed
resolute

needed

upstream

released

11.0.22

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

not-affected

code not present
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

not-affected

9.0.118-1
esm-apps/bionic

released

9.0.16-3ubuntu0.18.04.2+esm8
esm-apps/focal

released

9.0.31-1ubuntu0.9+esm3
esm-apps/jammy

released

9.0.58-1ubuntu0.2+esm4
esm-apps/noble

released

9.0.70-2ubuntu0.1+esm3
esm-apps/resolute

released

9.0.115-1ubuntu0.1
jammy

needed

noble

needed

questing

released

9.0.95-1ubuntu1.1
resolute

released

9.0.115-1ubuntu0.1

Показывать по

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.3
redhat
3 месяца назад

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 9.8
nvd
3 месяца назад

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 9.8
debian
3 месяца назад

Improper Input Validation vulnerability in Apache Tomcat. This issue ...

CVSS3: 9.8
github
3 месяца назад

Apache Tomcat - HTTP/2 request headers not validated

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

9.8 Critical

CVSS3