SB2026101003 - Anolis OS update for tomcat



SB2026101003 - Anolis OS update for tomcat

Published: October 10, 2026

Security Bulletin ID SB2026101003
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 14
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 79% Low 21%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 14 vulnerabilities.


1) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-34483)

CWE-ID: CWE-116 - Improper Encoding or Escaping of Output

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject arbitrary JSON into the JSON access log.

The vulnerability exists due to incomplete escaping in the JSON access log when handling requests with non-default Connector attributes relaxedPathChars and/or relaxedQueryChars. A remote attacker can send a specially crafted request to inject arbitrary JSON into the JSON access log.

Only configurations using non-default values for relaxedPathChars and/or relaxedQueryChars are affected.


2) Improper access control (CVE-ID: CVE-2026-43515)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass security constraints.

The vulnerability exists due to improper access control in HTTP method constraint processing when evaluating multiple security constraints for the same extension pattern. A remote attacker can send a request using an improperly constrained HTTP method to bypass security constraints.


3) Improper Certificate Validation (CVE-ID: CVE-2026-53434)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to authenticate with an invalid certificate.

The vulnerability exists due to improper certificate revocation validation in the FFM Connector when handling connections with invalid CRL configuration. A remote attacker can present an invalid certificate to authenticate with an invalid certificate.

Only configurations using the FFM Connector with invalid CRLs are affected.


4) Authentication Bypass by Capture-replay (CVE-ID: CVE-2026-55955)

CWE-ID: CWE-294 - Authentication Bypass by Capture-replay

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to replay protected communications.

The vulnerability exists due to missing replay protection in EncryptInterceptor when processing encrypted messages. A remote attacker can capture and resend previously valid messages to replay protected communications.


5) Improper Certificate Validation (CVE-ID: CVE-2026-73581)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass certificate revocation checks.

The vulnerability exists due to improper certificate validation in the OpenSSL and OpenSSL-FFM TLS implementations when validating a certificate that uses a keystore. A remote attacker can present a certificate subject to certificate revocation checks to bypass certificate revocation checks.

The issue affects both the OpenSSL and OpenSSL-FFM TLS implementations when the certificate uses a keystore.


6) Improper access control (CVE-ID: CVE-2026-76183)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass security constraints for WebSocket endpoints.

The vulnerability exists due to incorrect parsing of request paths as endpoint templates in WebSocket endpoint processing when processing a request for a WebSocket endpoint. A remote attacker can send a request with a crafted path to bypass security constraints for WebSocket endpoints.


7) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-77756)

CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause another user's request to fail.

The vulnerability exists due to improper handling of the Transfer-Encoding header in HTTP/1.0 request processing when processing an HTTP/1.0 request behind a reverse proxy. A remote attacker can send an HTTP/1.0 request with a Transfer-Encoding header to cause another user's request to fail.

The issue requires Tomcat to be located behind a reverse proxy.


8) Race condition (CVE-ID: CVE-2026-77762)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject trailer fields into another HTTP/2 request.

The vulnerability exists due to a race condition in the HPACK emitter when processing HTTP/2 requests with recycled pooled requests. A remote attacker can trigger the race condition to inject trailer fields into another HTTP/2 request.


9) Resource exhaustion (CVE-ID: CVE-2026-77791)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a busy wait in WebSocket close message handling when sending a WebSocket close message. A remote attacker can trigger the busy wait to cause a denial of service.


10) Resource exhaustion (CVE-ID: CVE-2026-78383)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of requests without a body in AJP request processing when processing an AJP request without a request body. A remote attacker can send an AJP request without a request body to cause a denial of service.

An affected request can pin an AJP processing thread.


11) Resource exhaustion (CVE-ID: CVE-2026-78437)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause another user's request to fail.

The vulnerability exists due to improper handling of malformed HTTP/2 requests in HTTP/2 request processing when handling a malformed HTTP/2 request. A remote attacker can send a malformed HTTP/2 request to cause another user's request to fail.

Successful exploitation depends on timing.


12) Race condition (CVE-ID: CVE-2026-79677)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a concurrency bug in asynchronous WebSocket write handling when performing asynchronous WebSocket writes. A remote attacker can trigger lost write timeouts to cause a denial of service.


13) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-86350)

CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a request header mix-up.

The vulnerability exists due to inconsistent interpretation of HTTP/2 requests in HTTP/2 request processing when handling HTTP/2 requests. A remote attacker can send a crafted HTTP/2 request to cause a request header mix-up.

The issue is a regression in the fix for CVE-2026-41293.


14) Input validation error (CVE-ID: CVE-2026-41293)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger unexpected application behavior.

The vulnerability exists due to improper input validation in HTTP/2 request header handling when exposing header values through the Servlet API. A remote attacker can send crafted HTTP/2 request headers to trigger unexpected application behavior.

This may affect applications that assume header values exposed through the Servlet API are specification compliant.


Remediation

Install update from vendor's website.