Advisories for Maven/Org.apache.tomcat/Tomcat-Util-Scan package

2026

Apache Tomcat - Logged effective web.xml is incomplete

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.