{"schema_version":"1.7.5","id":"SUSE-SU-2026:1058-1","published":"2026-03-26T09:46:45Z","modified":"2026-03-27T08:48:24.814862Z","related":["CVE-2020-13934","CVE-2020-13935","CVE-2020-13943","CVE-2020-17527","CVE-2021-24122","CVE-2021-25122","CVE-2021-25329","CVE-2021-30640","CVE-2021-33037","CVE-2021-41079","CVE-2021-43980","CVE-2022-23181","CVE-2022-42252","CVE-2023-24998","CVE-2023-28708","CVE-2023-28709","CVE-2023-41080","CVE-2023-42795","CVE-2023-44487","CVE-2023-45468","CVE-2023-46589","CVE-2024-21733","CVE-2024-23672","CVE-2024-24549","CVE-2024-34750","CVE-2024-38286","CVE-2024-50379","CVE-2024-52316","CVE-2024-54677","CVE-2025-24813","CVE-2025-31651","CVE-2025-46701","CVE-2025-48988","CVE-2025-48989","CVE-2025-49125","CVE-2025-52434","CVE-2025-52520","CVE-2025-53506","CVE-2025-55752","CVE-2025-55754","CVE-2025-61795","CVE-2025-66614","CVE-2026-24733"],"upstream":["CVE-2020-13934","CVE-2020-13935","CVE-2020-13943","CVE-2020-17527","CVE-2021-24122","CVE-2021-25122","CVE-2021-25329","CVE-2021-30640","CVE-2021-33037","CVE-2021-41079","CVE-2021-43980","CVE-2022-23181","CVE-2022-42252","CVE-2023-24998","CVE-2023-28708","CVE-2023-28709","CVE-2023-41080","CVE-2023-42795","CVE-2023-44487","CVE-2023-45468","CVE-2023-46589","CVE-2024-21733","CVE-2024-23672","CVE-2024-24549","CVE-2024-34750","CVE-2024-38286","CVE-2024-50379","CVE-2024-52316","CVE-2024-54677","CVE-2025-24813","CVE-2025-31651","CVE-2025-46701","CVE-2025-48988","CVE-2025-48989","CVE-2025-49125","CVE-2025-52434","CVE-2025-52520","CVE-2025-53506","CVE-2025-55752","CVE-2025-55754","CVE-2025-61795","CVE-2025-66614","CVE-2026-24733"],"summary":"Security update for tomcat","details":"This update for tomcat fixes the following issues:\n\nUpdate to Tomcat 9.0.115:\n\n- CVE-2025-48989: HTTP/2 protocol (including DNS over HTTPS) is vulnerable to 'MadeYouReset' DoS attack (bsc#1243895).\n- CVE-2025-52434: race condition on connection close when using the APR/Native connector could lead to a JVM crash\n  (bsc#1246389).\n- CVE-2025-53506: uncontrolled resource HTTP/2 client consumption vulnerability (bsc#1246318).\n- CVE-2025-66614: client certificate verification bypass due to virtual host mapping (bsc#1258371).\n- CVE-2026-24733: improper input validation on HTTP/0.9 requests (bsc#1258385).\n- CVE-2023-44487: Rapid reset attack (bsc#1216182).\n","affected":[{"package":{"name":"tomcat","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.115-3.160.1"}]}],"ecosystem_specific":{"binaries":[{"tomcat":"9.0.115-3.160.1","tomcat-admin-webapps":"9.0.115-3.160.1","tomcat-docs-webapp":"9.0.115-3.160.1","tomcat-el-3_0-api":"9.0.115-3.160.1","tomcat-javadoc":"9.0.115-3.160.1","tomcat-jsp-2_3-api":"9.0.115-3.160.1","tomcat-lib":"9.0.115-3.160.1","tomcat-servlet-4_0-api":"9.0.115-3.160.1","tomcat-webapps":"9.0.115-3.160.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1058-1.json"}},{"package":{"name":"tomcat","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.115-3.160.1"}]}],"ecosystem_specific":{"binaries":[{"tomcat":"9.0.115-3.160.1","tomcat-admin-webapps":"9.0.115-3.160.1","tomcat-docs-webapp":"9.0.115-3.160.1","tomcat-el-3_0-api":"9.0.115-3.160.1","tomcat-javadoc":"9.0.115-3.160.1","tomcat-jsp-2_3-api":"9.0.115-3.160.1","tomcat-lib":"9.0.115-3.160.1","tomcat-servlet-4_0-api":"9.0.115-3.160.1","tomcat-webapps":"9.0.115-3.160.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1058-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261058-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1216182"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243895"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246318"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246389"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258371"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258385"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259224"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-13934"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-13935"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-13943"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-17527"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-24122"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-25122"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-25329"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-30640"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-33037"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-41079"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-43980"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-23181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-42252"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-24998"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28708"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28709"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-41080"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-42795"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-44487"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-45468"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-46589"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-21733"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-23672"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-24549"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-34750"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-38286"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-50379"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-52316"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-54677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-24813"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-31651"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-46701"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-48988"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-48989"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-49125"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-52434"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-52520"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-53506"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-55752"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-55754"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-61795"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-66614"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24733"}]}