Skip to content

[GHSA-8mc5-53m5-3qj2] Apache Tomcat has an Improper Input Validation vulnerability#7401

Closed
tkwilli94 wants to merge 1 commit into
tkwilli94/advisory-improvement-7401from
tkwilli94-GHSA-8mc5-53m5-3qj2
Closed

[GHSA-8mc5-53m5-3qj2] Apache Tomcat has an Improper Input Validation vulnerability#7401
tkwilli94 wants to merge 1 commit into
tkwilli94/advisory-improvement-7401from
tkwilli94-GHSA-8mc5-53m5-3qj2

Conversation

@tkwilli94
Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • References

Comments
The code change to fix the CVE were made in tomcat-coyote, not tomcat-catalina. The specific commit (for the Tomcat 9 fix) is apache/tomcat@95f7778 (See Tomcat 9.0.116 release notes). The only functional change is in org/apache/tomcat/util/** which is part of tomcat-coyote and not tomcat-catalina (see build.xml)

@github-actions github-actions Bot changed the base branch from main to tkwilli94/advisory-improvement-7401 April 15, 2026 20:50
@tkwilli94
Copy link
Copy Markdown
Author

The Form submission didn't recognize the CVSS v3 vector string as valid for some reason and removed it as part of my PR. As I cannot update this PR to reinstate the CVSS v3 vector string, I will cancel this PR and open another one manually instead of using the form

@tkwilli94 tkwilli94 closed this Apr 15, 2026
@github-actions github-actions Bot deleted the tkwilli94-GHSA-8mc5-53m5-3qj2 branch April 15, 2026 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant