<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>certdesk — certificate-related CVEs</title><description>New CVEs for OpenSSL, Nginx, Apache, Tomcat, IIS and certbot from NVD (daily)</description><link>https://certdesk.dev/en/cve/</link><item><title>CVE-2026-63073 · OpenSSL (CRITICAL 9.8)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-63073</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-63073</guid><description>Issue summary: OpenSSL CMP response validation passed an unexpected response
sender distinguished name directly as the format string to `ERR_raise_data()`.

Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client
that enforces an expected sender or uses a pinned server certificate whose
subject becomes the default expected sender.

CWE: CWE-134 (Use of Externally-Controlled </description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>OpenSSL</category></item><item><title>CVE-2026-75803 · OpenSSL (CRITICAL 9.1)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-75803</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-75803</guid><description>Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty
ciphertext can report success without verifying the supplied authentication
tag when the operation is finalized by calling the EVP_Cipher() function.

Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and
expecting the call to check the AEAD tag may accept forged messages.

CWE: CWE-354 (Improper Validatio</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>OpenSSL</category></item><item><title>CVE-2026-65182 · Tomcat (CRITICAL 9.1)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-65182</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-65182</guid><description>Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.



This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 throu</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-65637 · Tomcat (CRITICAL 9.8)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-65637</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-65637</guid><description>Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.



This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120.



Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-65905 · Tomcat (CRITICAL 9.8)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-65905</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-65905</guid><description>Authentication Bypass by Capture-replay vulnerability in Apache Tomcat&apos;s DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST 
authenticated request with a nonceCount on the upper boundary of the 
replay window then that request is replayable once only while the 
associated nonceCount remains within the replay window.



 

This issue affects Apache Tomcat: </description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-68525 · Tomcat (CRITICAL 9.1)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-68525</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-68525</guid><description>Incorrect Authorization vulnerability in Apache Tomcat&apos;s FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET.







This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.







The following versions were EOL at the time the CVE was created bu</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-14457 · OpenSSL (HIGH 7.5)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-14457</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-14457</guid><description>Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)
enabled, and only the private key (with no associated certificate) configured locally,
a NULL pointer dereference may occur when the remote peer solicits raw public keys and
also sends the typically omitted &quot;signature_algorithms_cert&quot; TLS extension.

Impact summary: The impact is limited to a possible Denial of </description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>OpenSSL</category></item><item><title>CVE-2026-18798 · OpenSSL (HIGH 7.5)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-18798</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-18798</guid><description>Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel creation fails for initial packet.

Impact summary: Double free leads to heap corruption, which typically results in 
termination of QUIC server process, leading to Denial of Service. There is so
far no evidence that this double free is exploitable for remote code execution,
thus it is considered highly impro</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>OpenSSL</category></item><item><title>CVE-2026-54874 · OpenSSL (HIGH 7.5)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-54874</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-54874</guid><description>Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes OpenSSL to buffer far more memory than the record
itself requires.

Impact summary: A peer can use a small amount of network traffic to make an
OpenSSL DTLS endpoint retain a disproportionately large amount of memory,
which may lead to a Denial of Service.

CWE: CWE-405: Asymmetric Resource Consumptio</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>OpenSSL</category></item><item><title>CVE-2026-63072 · OpenSSL (HIGH 7.5)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-63072</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-63072</guid><description>Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based
on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive
can write and cleanse more bytes than that query reports, causing an 8-byte
out-of-bounds heap write.

Impact summary: An attacker who supplies a crafted CMS message can trigger a
deterministic 8-byte out-of-bounds heap write when the victim decry</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>OpenSSL</category></item><item><title>CVE-2026-63075 · OpenSSL (HIGH 7.5)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-63075</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-63075</guid><description>Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly
sends ack-eliciting packets while not acknowledging ACK-only responses, the
QUIC stack can retain ACK-only packet metadata for the lifetime of the
connection.

Impact summary: A remote peer that can complete a QUIC handshake can
cause connection-scoped memory growth which may lead to Denial of Service
through memory exh</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>OpenSSL</category></item><item><title>CVE-2026-63076 · OpenSSL (HIGH 7.5)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-63076</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-63076</guid><description>Issue summary: OpenSSL CMP password based protection verification only
checks whether the protectionAlg parameter was not NULL and not its
ASN.1 type, before treating it as a PBMParameter. A crafted message can
contain a parameter of a different type, which is then dereferenced as an
invalid pointer.

Impact summary: A remote, unauthenticated attacker can crash an application
acting as a CMP serve</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>OpenSSL</category></item><item><title>CVE-2026-65183 · Tomcat (HIGH 8.1)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-65183</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-65183</guid><description>Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket.



This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.



Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes t</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-65927 · Tomcat (HIGH 7.5)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-65927</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-65927</guid><description>Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule.







This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.



The following versions were EOL at the time the CVE was created but are 
known to be</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-66422 · Tomcat (HIGH 8.1)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-66422</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-66422</guid><description>Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole().



This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120.



The following versions were EOL at the time the CVE wa</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-68569 · Tomcat (HIGH 8.1)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-68569</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-68569</guid><description>Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.



This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.







The following versions were EOL at the time the CVE was </description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-68763 · Tomcat (HIGH 7.5)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-68763</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-68763</guid><description>Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset



This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120.



The following versions were EOL at the time the CVE was created but are 
known to be affected: from 8.5.59 through 8.5.100. O</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-63074 · OpenSSL (MEDIUM 5.9)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-63074</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-63074</guid><description>Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches
additional certificates (extraCerts) sent in a CMP message, but never expunges
them (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX
frequently, this cache of extraCerts may grow unboundedly, and a malicious
client may flood a CMP server with requests driving this growth.

Impact summary: Users utilizing</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>OpenSSL</category></item><item><title>CVE-2026-73180 · Tomcat (MEDIUM 6.8)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-73180</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-73180</guid><description>Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended.



This issue affects Apache Tomcat: from 11.0.0-M1</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-66299 · Tomcat (MEDIUM 5.3)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-66299</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-66299</guid><description>Uncontrolled Resource Consumption vulnerability in Apache Tomcat&apos;s WebSocket chat example.

This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.

Users are recommended to remove the examples web application or </description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-59083 · Tomcat (CRITICAL 9.1)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-59083</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-59083</guid><description>Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat&apos;s rewrite valve allowed security constraint bypass for some configurations.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.

Users are recom</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-59084 · Tomcat (CRITICAL 9.1)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-59084</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-59084</guid><description>Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support </description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-53434 · Tomcat (CRITICAL 9.1)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-53434</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-53434</guid><description>Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.

Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-55276 · Tomcat (CRITICAL 9.1)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-55276</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-55276</guid><description>Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support </description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-53404 · Tomcat (HIGH 7.3)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-53404</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-53404</guid><description>Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat&apos;s rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support m</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-55957 · Tomcat (HIGH 7.3)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-55957</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-55957</guid><description>Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.

U</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-50229 · Tomcat (MEDIUM 6.1)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-50229</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-50229</guid><description>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.

User</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-55955 · Tomcat (MEDIUM 6.5)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-55955</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-55955</guid><description>Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.

Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, whi</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item><item><title>CVE-2026-55956 · Tomcat (MEDIUM 6.5)</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-55956</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-55956</guid><description>Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>Tomcat</category></item></channel></rss>