VDB
GCVE-110-MAGEIA-2026-139
GCVE-110-MAGEIA-2026-139
Advisory Published
Unbounded read in WebDAV LOCK and PROPFIND handling. (CVE-2026-41284)
HTTP/2 request headers not validated. (CVE-2026-41293)
WebSocket authentication header exposure. (CVE-2026-42498)
Digest authenticator will authenticate any unknown user.
(CVE-2026-43512)
LockOutRealm treats user names as case-sensitive. (CVE-2026-43513)
AJP secret compared in non-constant time. (CVE-2026-43514)
Security constraints not correctly applied. (CVE-2026-43515)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | tomcat | 0 (affected), 9.0.118-1.mga9 (unaffected) | — |
References
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.