|
1 | 1 | { |
2 | 2 | "schema_version": "1.4.0", |
3 | 3 | "id": "GHSA-69r9-qgr7-g2wj", |
4 | | - "modified": "2026-04-10T22:07:50Z", |
| 4 | + "modified": "2026-04-15T22:36:04Z", |
5 | 5 | "published": "2026-04-09T21:31:30Z", |
6 | 6 | "aliases": [ |
7 | 7 | "CVE-2026-34486" |
|
18 | 18 | { |
19 | 19 | "package": { |
20 | 20 | "ecosystem": "Maven", |
21 | | - "name": "org.apache.tomcat:tomcat-catalina" |
| 21 | + "name": "org.apache.tomcat:tomcat-tribes" |
22 | 22 | }, |
23 | 23 | "ranges": [ |
24 | 24 | { |
|
40 | 40 | { |
41 | 41 | "package": { |
42 | 42 | "ecosystem": "Maven", |
43 | | - "name": "org.apache.tomcat:tomcat-catalina" |
| 43 | + "name": "org.apache.tomcat:tomcat-tribes" |
44 | 44 | }, |
45 | 45 | "ranges": [ |
46 | 46 | { |
|
62 | 62 | { |
63 | 63 | "package": { |
64 | 64 | "ecosystem": "Maven", |
65 | | - "name": "org.apache.tomcat:tomcat-catalina" |
| 65 | + "name": "org.apache.tomcat:tomcat-tribes" |
66 | 66 | }, |
67 | 67 | "ranges": [ |
68 | 68 | { |
|
146 | 146 | "versions": [ |
147 | 147 | "9.0.116" |
148 | 148 | ] |
149 | | - }, |
150 | | - { |
151 | | - "package": { |
152 | | - "ecosystem": "Maven", |
153 | | - "name": "org.apache.tomcat.embed:tomcat-embed-core" |
154 | | - }, |
155 | | - "ranges": [ |
156 | | - { |
157 | | - "type": "ECOSYSTEM", |
158 | | - "events": [ |
159 | | - { |
160 | | - "introduced": "11.0.20" |
161 | | - }, |
162 | | - { |
163 | | - "fixed": "11.0.21" |
164 | | - } |
165 | | - ] |
166 | | - } |
167 | | - ], |
168 | | - "versions": [ |
169 | | - "11.0.20" |
170 | | - ] |
171 | | - }, |
172 | | - { |
173 | | - "package": { |
174 | | - "ecosystem": "Maven", |
175 | | - "name": "org.apache.tomcat.embed:tomcat-embed-core" |
176 | | - }, |
177 | | - "ranges": [ |
178 | | - { |
179 | | - "type": "ECOSYSTEM", |
180 | | - "events": [ |
181 | | - { |
182 | | - "introduced": "10.1.53" |
183 | | - }, |
184 | | - { |
185 | | - "fixed": "10.1.54" |
186 | | - } |
187 | | - ] |
188 | | - } |
189 | | - ], |
190 | | - "versions": [ |
191 | | - "10.1.53" |
192 | | - ] |
193 | | - }, |
194 | | - { |
195 | | - "package": { |
196 | | - "ecosystem": "Maven", |
197 | | - "name": "org.apache.tomcat.embed:tomcat-embed-core" |
198 | | - }, |
199 | | - "ranges": [ |
200 | | - { |
201 | | - "type": "ECOSYSTEM", |
202 | | - "events": [ |
203 | | - { |
204 | | - "introduced": "9.0.116" |
205 | | - }, |
206 | | - { |
207 | | - "fixed": "9.0.117" |
208 | | - } |
209 | | - ] |
210 | | - } |
211 | | - ], |
212 | | - "versions": [ |
213 | | - "9.0.116" |
214 | | - ] |
215 | 149 | } |
216 | 150 | ], |
217 | 151 | "references": [ |
218 | 152 | { |
219 | 153 | "type": "ADVISORY", |
220 | 154 | "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34486" |
221 | 155 | }, |
| 156 | + { |
| 157 | + "type": "WEB", |
| 158 | + "url": "https://github.com/apache/tomcat/commit/1fab40ccc752e22639eccfe290d5624afad7eccd" |
| 159 | + }, |
| 160 | + { |
| 161 | + "type": "WEB", |
| 162 | + "url": "https://github.com/apache/tomcat/commit/55f3eb9148233054fccfdf761141c6894a050be1" |
| 163 | + }, |
| 164 | + { |
| 165 | + "type": "WEB", |
| 166 | + "url": "https://github.com/apache/tomcat/commit/776e12b3e2b0b4507b8a3b62c187ceb0b74bf418" |
| 167 | + }, |
222 | 168 | { |
223 | 169 | "type": "PACKAGE", |
224 | 170 | "url": "https://github.com/apache/tomcat" |
225 | 171 | }, |
226 | 172 | { |
227 | 173 | "type": "WEB", |
228 | 174 | "url": "https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly" |
| 175 | + }, |
| 176 | + { |
| 177 | + "type": "WEB", |
| 178 | + "url": "https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.54" |
| 179 | + }, |
| 180 | + { |
| 181 | + "type": "WEB", |
| 182 | + "url": "https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.21" |
| 183 | + }, |
| 184 | + { |
| 185 | + "type": "WEB", |
| 186 | + "url": "https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.117" |
| 187 | + }, |
| 188 | + { |
| 189 | + "type": "WEB", |
| 190 | + "url": "https://www.herodevs.com/vulnerability-directory/cve-2026-34486" |
229 | 191 | } |
230 | 192 | ], |
231 | 193 | "database_specific": { |
|
0 commit comments