Search CVE reports


Toggle filters

2031 – 2040 of 58108 results

Status is adjusted based on your filters.


CVE-2026-68569

Medium priority
Needs evaluation

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Not affected
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages

CVE-2026-68525

Medium priority
Needs evaluation

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Not affected
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages

CVE-2026-66422

Medium priority
Needs evaluation

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Not affected
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages

CVE-2026-65927

Medium priority
Needs evaluation

Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Not affected
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages

CVE-2026-65905

Medium priority
Needs evaluation

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Not affected
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages

CVE-2026-65637

Medium priority
Needs evaluation

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Not affected
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages

CVE-2026-65183

Medium priority
Needs evaluation

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Not affected
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages

CVE-2026-65182

Medium priority
Needs evaluation

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Not affected
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages

CVE-2026-80101

Medium priority
Needs evaluation

A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per-line parameters independently rather than ensuring their combined values are...

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-77680

Medium priority
Needs evaluation

An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed memory amplification when a client repeated the same range many times in a single...

2 affected packages

libsoup2.4, libsoup3

Package 16.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages