Skip to content

Commit b2d91bb

Browse files
1 parent 2920c23 commit b2d91bb

File tree

1 file changed

+69
-16
lines changed

1 file changed

+69
-16
lines changed

advisories/github-reviewed/2026/04/GHSA-h468-7pvh-8vr8/GHSA-h468-7pvh-8vr8.json

Lines changed: 69 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-h468-7pvh-8vr8",
4-
"modified": "2026-04-10T21:32:09Z",
4+
"modified": "2026-04-15T21:33:40Z",
55
"published": "2026-04-09T21:31:29Z",
66
"aliases": [
77
"CVE-2026-29146"
@@ -22,7 +22,7 @@
2222
{
2323
"package": {
2424
"ecosystem": "Maven",
25-
"name": "org.apache.tomcat:tomcat-catalina"
25+
"name": "org.apache.tomcat:tomcat-tribes"
2626
},
2727
"ranges": [
2828
{
@@ -41,7 +41,7 @@
4141
{
4242
"package": {
4343
"ecosystem": "Maven",
44-
"name": "org.apache.tomcat:tomcat-catalina"
44+
"name": "org.apache.tomcat:tomcat-tribes"
4545
},
4646
"ranges": [
4747
{
@@ -60,7 +60,7 @@
6060
{
6161
"package": {
6262
"ecosystem": "Maven",
63-
"name": "org.apache.tomcat:tomcat-catalina"
63+
"name": "org.apache.tomcat:tomcat-tribes"
6464
},
6565
"ranges": [
6666
{
@@ -70,11 +70,14 @@
7070
"introduced": "11.0.0-M1"
7171
},
7272
{
73-
"fixed": "11.0.19"
73+
"fixed": "11.0.20"
7474
}
7575
]
7676
}
77-
]
77+
],
78+
"database_specific": {
79+
"last_known_affected_version_range": "<= 11.0.18"
80+
}
7881
},
7982
{
8083
"package": {
@@ -127,7 +130,29 @@
127130
"introduced": "11.0.0-M1"
128131
},
129132
{
130-
"fixed": "11.0.19"
133+
"fixed": "11.0.20"
134+
}
135+
]
136+
}
137+
],
138+
"database_specific": {
139+
"last_known_affected_version_range": "<= 11.0.18"
140+
}
141+
},
142+
{
143+
"package": {
144+
"ecosystem": "Maven",
145+
"name": "org.apache.tomcat:tomcat-tribes"
146+
},
147+
"ranges": [
148+
{
149+
"type": "ECOSYSTEM",
150+
"events": [
151+
{
152+
"introduced": "8.5.38"
153+
},
154+
{
155+
"last_affected": "8.5.100"
131156
}
132157
]
133158
}
@@ -136,17 +161,17 @@
136161
{
137162
"package": {
138163
"ecosystem": "Maven",
139-
"name": "org.apache.tomcat.embed:tomcat-embed-core"
164+
"name": "org.apache.tomcat:tomcat"
140165
},
141166
"ranges": [
142167
{
143168
"type": "ECOSYSTEM",
144169
"events": [
145170
{
146-
"introduced": "9.0.13"
171+
"introduced": "8.5.38"
147172
},
148173
{
149-
"fixed": "9.0.116"
174+
"last_affected": "8.5.100"
150175
}
151176
]
152177
}
@@ -155,17 +180,17 @@
155180
{
156181
"package": {
157182
"ecosystem": "Maven",
158-
"name": "org.apache.tomcat.embed:tomcat-embed-core"
183+
"name": "org.apache.tomcat:tomcat-tribes"
159184
},
160185
"ranges": [
161186
{
162187
"type": "ECOSYSTEM",
163188
"events": [
164189
{
165-
"introduced": "10.1.50"
190+
"introduced": "7.0.100"
166191
},
167192
{
168-
"fixed": "10.1.53"
193+
"last_affected": "7.0.109"
169194
}
170195
]
171196
}
@@ -174,17 +199,17 @@
174199
{
175200
"package": {
176201
"ecosystem": "Maven",
177-
"name": "org.apache.tomcat.embed:tomcat-embed-core"
202+
"name": "org.apache.tomcat:tomcat"
178203
},
179204
"ranges": [
180205
{
181206
"type": "ECOSYSTEM",
182207
"events": [
183208
{
184-
"introduced": "11.0.0-M1"
209+
"introduced": "7.0.100"
185210
},
186211
{
187-
"fixed": "11.0.19"
212+
"last_affected": "7.0.109"
188213
}
189214
]
190215
}
@@ -196,6 +221,18 @@
196221
"type": "ADVISORY",
197222
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29146"
198223
},
224+
{
225+
"type": "WEB",
226+
"url": "https://github.com/apache/tomcat/commit/0112ed22abfccc3d54e44d91eb08804d0886acd1"
227+
},
228+
{
229+
"type": "WEB",
230+
"url": "https://github.com/apache/tomcat/commit/607ebc0fa522bd9e8c05517baa2d179bbd1e659c"
231+
},
232+
{
233+
"type": "WEB",
234+
"url": "https://github.com/apache/tomcat/commit/6d955cceca841f2eabf2d6c46b59a8c7e1cd6eaa"
235+
},
199236
{
200237
"type": "PACKAGE",
201238
"url": "https://github.com/apache/tomcat"
@@ -204,6 +241,22 @@
204241
"type": "WEB",
205242
"url": "https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w"
206243
},
244+
{
245+
"type": "WEB",
246+
"url": "https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.53"
247+
},
248+
{
249+
"type": "WEB",
250+
"url": "https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20"
251+
},
252+
{
253+
"type": "WEB",
254+
"url": "https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.116"
255+
},
256+
{
257+
"type": "WEB",
258+
"url": "https://www.herodevs.com/vulnerability-directory/cve-2026-29146"
259+
},
207260
{
208261
"type": "WEB",
209262
"url": "http://www.openwall.com/lists/oss-security/2026/04/09/24"

0 commit comments

Comments
 (0)