VDB
GCVE-110-MAGEIA-2026-323
GCVE-110-MAGEIA-2026-323
Advisory Published
The updated packages fix security vulnerabilities:
XSS in number guess example. (CVE-2026-50229)
Bad ornext processing in RewriteValve. (CVE-2026-53404)
Invalid CRL configuration doesn't trigger failure for FFM Connector.
(CVE-2026-53434)
Logged effective web.xml is incomplete. (CVE-2026-55276)
EncryptInterceptor not protected against replay attacks.
(CVE-2026-55955)
Security constraints for default servlet ignored method.
(CVE-2026-55956)
Authentication bypass with JNDIRealm and GSSAPI authenticated bind.
(CVE-2026-55957)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | tomcat | 0 (affected), 9.0.119-1.mga9 (unaffected), 0 (affected), 9.0.119-1.mga9 (unaffected) | — |
| Mageia | tomcat | 0 (affected), 9.0.119-1.mga10 (unaffected), 0 (affected), 9.0.119-1.mga10 (unaffected) | — |
References
Browse GCVE Records
69,213 records in the GCVE database · Updated August 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.