It was discovered that Tomcat incorrectly handled authorization when multiple method constraints defined the same HTTP method. A remote attacker could possibly use this issue to bypass authorization restrictions. (CVE-2026-43515) It was discovered that the Tomcat number guess example application did not properly sanitize user-supplied input.
USN-8551-1: Tomcat vulnerabilities
calendar_today
July 15, 2026
domain
ubuntu