SB2026101003 - Anolis OS update for tomcat
Published: October 10, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 14 vulnerabilities.
1) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-34483)
CWE-ID: CWE-116 - Improper Encoding or Escaping of Output
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject arbitrary JSON into the JSON access log.
The vulnerability exists due to incomplete escaping in the JSON access log when handling requests with non-default Connector attributes relaxedPathChars and/or relaxedQueryChars. A remote attacker can send a specially crafted request to inject arbitrary JSON into the JSON access log.
Only configurations using non-default values for relaxedPathChars and/or relaxedQueryChars are affected.
2) Improper access control (CVE-ID: CVE-2026-43515)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security constraints.
The vulnerability exists due to improper access control in HTTP method constraint processing when evaluating multiple security constraints for the same extension pattern. A remote attacker can send a request using an improperly constrained HTTP method to bypass security constraints.
3) Improper Certificate Validation (CVE-ID: CVE-2026-53434)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to authenticate with an invalid certificate.
The vulnerability exists due to improper certificate revocation validation in the FFM Connector when handling connections with invalid CRL configuration. A remote attacker can present an invalid certificate to authenticate with an invalid certificate.
Only configurations using the FFM Connector with invalid CRLs are affected.
4) Authentication Bypass by Capture-replay (CVE-ID: CVE-2026-55955)
CWE-ID: CWE-294 - Authentication Bypass by Capture-replay
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to replay protected communications.
The vulnerability exists due to missing replay protection in EncryptInterceptor when processing encrypted messages. A remote attacker can capture and resend previously valid messages to replay protected communications.
5) Improper Certificate Validation (CVE-ID: CVE-2026-73581)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass certificate revocation checks.
The vulnerability exists due to improper certificate validation in the OpenSSL and OpenSSL-FFM TLS implementations when validating a certificate that uses a keystore. A remote attacker can present a certificate subject to certificate revocation checks to bypass certificate revocation checks.
The issue affects both the OpenSSL and OpenSSL-FFM TLS implementations when the certificate uses a keystore.
6) Improper access control (CVE-ID: CVE-2026-76183)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security constraints for WebSocket endpoints.
The vulnerability exists due to incorrect parsing of request paths as endpoint templates in WebSocket endpoint processing when processing a request for a WebSocket endpoint. A remote attacker can send a request with a crafted path to bypass security constraints for WebSocket endpoints.
7) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-77756)
CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause another user's request to fail.
The vulnerability exists due to improper handling of the Transfer-Encoding header in HTTP/1.0 request processing when processing an HTTP/1.0 request behind a reverse proxy. A remote attacker can send an HTTP/1.0 request with a Transfer-Encoding header to cause another user's request to fail.
The issue requires Tomcat to be located behind a reverse proxy.
8) Race condition (CVE-ID: CVE-2026-77762)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject trailer fields into another HTTP/2 request.
The vulnerability exists due to a race condition in the HPACK emitter when processing HTTP/2 requests with recycled pooled requests. A remote attacker can trigger the race condition to inject trailer fields into another HTTP/2 request.
9) Resource exhaustion (CVE-ID: CVE-2026-77791)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a busy wait in WebSocket close message handling when sending a WebSocket close message. A remote attacker can trigger the busy wait to cause a denial of service.
10) Resource exhaustion (CVE-ID: CVE-2026-78383)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of requests without a body in AJP request processing when processing an AJP request without a request body. A remote attacker can send an AJP request without a request body to cause a denial of service.
An affected request can pin an AJP processing thread.
11) Resource exhaustion (CVE-ID: CVE-2026-78437)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause another user's request to fail.
The vulnerability exists due to improper handling of malformed HTTP/2 requests in HTTP/2 request processing when handling a malformed HTTP/2 request. A remote attacker can send a malformed HTTP/2 request to cause another user's request to fail.
Successful exploitation depends on timing.
12) Race condition (CVE-ID: CVE-2026-79677)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a concurrency bug in asynchronous WebSocket write handling when performing asynchronous WebSocket writes. A remote attacker can trigger lost write timeouts to cause a denial of service.
13) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-86350)
CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a request header mix-up.
The vulnerability exists due to inconsistent interpretation of HTTP/2 requests in HTTP/2 request processing when handling HTTP/2 requests. A remote attacker can send a crafted HTTP/2 request to cause a request header mix-up.
The issue is a regression in the fix for CVE-2026-41293.
14) Input validation error (CVE-ID: CVE-2026-41293)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger unexpected application behavior.
The vulnerability exists due to improper input validation in HTTP/2 request header handling when exposing header values through the Servlet API. A remote attacker can send crafted HTTP/2 request headers to trigger unexpected application behavior.
This may affect applications that assume header values exposed through the Servlet API are specification compliant.
Remediation
Install update from vendor's website.