{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"Critical"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"tomcat security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for tomcat is now available for openEuler-20.03-LTS-SP4",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process.\n\nSecurity Fix(es):\n\nImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.(CVE-2026-50229)\n\nAlways-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.(CVE-2026-53404)\n\nDetection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.(CVE-2026-53434)\n\nAlways-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.(CVE-2026-55276)\n\nImproper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.(CVE-2026-55955)\n\nImproper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.(CVE-2026-55956)\n\nMissing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.\n\nUsers are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.(CVE-2026-55957)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for tomcat is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"Critical",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"tomcat",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2026-2947",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2947"
			},
			{
				"summary":"CVE-2026-50229",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-50229&packageName=tomcat"
			},
			{
				"summary":"CVE-2026-53404",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-53404&packageName=tomcat"
			},
			{
				"summary":"CVE-2026-53434",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-53434&packageName=tomcat"
			},
			{
				"summary":"CVE-2026-55276",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-55276&packageName=tomcat"
			},
			{
				"summary":"CVE-2026-55955",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-55955&packageName=tomcat"
			},
			{
				"summary":"CVE-2026-55956",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-55956&packageName=tomcat"
			},
			{
				"summary":"CVE-2026-55957",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-55957&packageName=tomcat"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50229"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53404"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53434"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55276"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55955"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55956"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55957"
			},
			{
				"summary":"openEuler-SA-2026-2947 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2947.json"
			}
		],
		"title":"An update for tomcat is now available for openEuler-20.03-LTS-SP4",
		"tracking":{
			"initial_release_date":"2026-07-13T11:35:25+08:00",
			"revision_history":[
				{
					"date":"2026-07-13T11:35:25+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2026-07-13T11:35:25+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2026-07-13T11:35:25+08:00",
			"id":"openEuler-SA-2026-2947",
			"version":"1.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:20.03-LTS-SP4"
									},
									"product_id":"openEuler-20.03-LTS-SP4",
									"name":"openEuler-20.03-LTS-SP4"
								},
								"name":"openEuler-20.03-LTS-SP4",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"noarch",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:20.03-LTS-SP4"
									},
									"product_id":"tomcat-9.0.119-1.oe2003sp4.noarch.rpm",
									"name":"tomcat-9.0.119-1.oe2003sp4.noarch.rpm"
								},
								"name":"tomcat-9.0.119-1.oe2003sp4.noarch.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:20.03-LTS-SP4"
									},
									"product_id":"tomcat-help-9.0.119-1.oe2003sp4.noarch.rpm",
									"name":"tomcat-help-9.0.119-1.oe2003sp4.noarch.rpm"
								},
								"name":"tomcat-help-9.0.119-1.oe2003sp4.noarch.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:20.03-LTS-SP4"
									},
									"product_id":"tomcat-jsvc-9.0.119-1.oe2003sp4.noarch.rpm",
									"name":"tomcat-jsvc-9.0.119-1.oe2003sp4.noarch.rpm"
								},
								"name":"tomcat-jsvc-9.0.119-1.oe2003sp4.noarch.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:20.03-LTS-SP4"
									},
									"product_id":"tomcat-9.0.119-1.oe2003sp4.src.rpm",
									"name":"tomcat-9.0.119-1.oe2003sp4.src.rpm"
								},
								"name":"tomcat-9.0.119-1.oe2003sp4.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-20.03-LTS-SP4",
				"product_reference":"tomcat-9.0.119-1.oe2003sp4.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
					"name":"tomcat-9.0.119-1.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-20.03-LTS-SP4",
				"product_reference":"tomcat-help-9.0.119-1.oe2003sp4.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
					"name":"tomcat-help-9.0.119-1.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-20.03-LTS-SP4",
				"product_reference":"tomcat-jsvc-9.0.119-1.oe2003sp4.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
					"name":"tomcat-jsvc-9.0.119-1.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-20.03-LTS-SP4",
				"product_reference":"tomcat-9.0.119-1.oe2003sp4.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src",
					"name":"tomcat-9.0.119-1.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2026-50229",
			"notes":[
				{
					"text":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					],
					"details":"tomcat security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2947"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":6.1,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					]
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2026-50229"
		},
		{
			"cve":"CVE-2026-53404",
			"notes":[
				{
					"text":"Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					],
					"details":"tomcat security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2947"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":7.3,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
						"version":"3.1"
					},
					"products":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-53404"
		},
		{
			"cve":"CVE-2026-53434",
			"notes":[
				{
					"text":"Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					],
					"details":"tomcat security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2947"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"CRITICAL",
						"baseScore":9.1,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					]
				}
			],
			"threats":[
				{
					"details":"Critical",
					"category":"impact"
				}
			],
			"title":"CVE-2026-53434"
		},
		{
			"cve":"CVE-2026-55276",
			"notes":[
				{
					"text":"Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					],
					"details":"tomcat security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2947"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"CRITICAL",
						"baseScore":9.1,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					]
				}
			],
			"threats":[
				{
					"details":"Critical",
					"category":"impact"
				}
			],
			"title":"CVE-2026-55276"
		},
		{
			"cve":"CVE-2026-55955",
			"notes":[
				{
					"text":"Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					],
					"details":"tomcat security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2947"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":6.5,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					]
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2026-55955"
		},
		{
			"cve":"CVE-2026-55956",
			"notes":[
				{
					"text":"Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					],
					"details":"tomcat security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2947"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":6.5,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					]
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2026-55956"
		},
		{
			"cve":"CVE-2026-55957",
			"notes":[
				{
					"text":"Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.\n\nUsers are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
					"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					],
					"details":"tomcat security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2947"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":7.3,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
						"version":"3.1"
					},
					"products":[
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-help-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-jsvc-9.0.119-1.oe2003sp4.noarch",
						"openEuler-20.03-LTS-SP4:tomcat-9.0.119-1.oe2003sp4.src"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-55957"
		}
	]
}