VDB

GCVE-110-MAGEIA-2026-323

GCVE-110-MAGEIA-2026-323
Advisory Published
Vulnetix · Advisory published August 5, 2026
The updated packages fix security vulnerabilities: XSS in number guess example. (CVE-2026-50229) Bad ornext processing in RewriteValve. (CVE-2026-53404) Invalid CRL configuration doesn't trigger failure for FFM Connector. (CVE-2026-53434) Logged effective web.xml is incomplete. (CVE-2026-55276) EncryptInterceptor not protected against replay attacks. (CVE-2026-55955) Security constraints for default servlet ignored method. (CVE-2026-55956) Authentication bypass with JNDIRealm and GSSAPI authenticated bind. (CVE-2026-55957)

Affected Products

VendorProductVersionsPlatforms
Mageiatomcat0 (affected), 9.0.119-1.mga9 (unaffected), 0 (affected), 9.0.119-1.mga9 (unaffected)
Mageiatomcat0 (affected), 9.0.119-1.mga10 (unaffected), 0 (affected), 9.0.119-1.mga10 (unaffected)

Browse GCVE Records

69,213 records in the GCVE database · Updated August 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›