Debian Package Tracker
Register | Log in
Subscribe

tomcat-native

Tomcat native library using the Apache Portable Runtime

Choose email to subscribe with

general
  • source: tomcat-native (main)
  • version: 2.0.16-1
  • maintainer: Debian Java Maintainers (archive) (DMD)
  • uploaders: Emmanuel Bourg [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.2.26-1
  • o-o-sec: 1.2.26+really1.3.7-1
  • oldstable: 1.2.35-1
  • stable: 1.3.1-1
  • testing: 2.0.16-1
  • unstable: 2.0.16-1
versioned links
  • 1.2.26-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.2.26+really1.3.7-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.2.35-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.3.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.16-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libtcnative-2
action needed
3 security issues in bookworm high

There are 3 open security issues in bookworm.

3 important issues:
  • CVE-2026-86243: Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.
  • CVE-2026-86246: Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fix the issue.
  • CVE-2026-86247: Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fixes the issue.
Created: 2026-09-23 Last update: 2026-09-29 11:00
1 open merge request in Salsa normal
There is 1 open merge request for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2026-10-03 Last update: 2026-10-03 03:03
3 low-priority security issues in trixie low

There are 3 open security issues in trixie.

3 issues left for the package maintainer to handle:
  • CVE-2026-86243: (needs triaging) Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.
  • CVE-2026-86246: (needs triaging) Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fix the issue.
  • CVE-2026-86247: (needs triaging) Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fixes the issue.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-09-23 Last update: 2026-09-29 11:00
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-09-23] tomcat-native 2.0.16-1 MIGRATED to testing (Debian testing watch)
  • [2026-09-18] Accepted tomcat-native 2.0.16-1 (source) into unstable (Emmanuel Bourg)
  • [2026-06-06] Accepted tomcat-native 1.2.26+really1.3.7-1 (source) into oldoldstable-security (Markus Koschany)
  • [2026-04-06] tomcat-native 2.0.14-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-01] Accepted tomcat-native 2.0.14-1 (source amd64) into unstable (Debian FTP Masters) (signed by: Emmanuel Bourg)
  • [2026-03-22] tomcat-native 1.3.7-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-16] Accepted tomcat-native 1.3.7-1 (source) into unstable (Emmanuel Bourg)
  • [2024-10-30] tomcat-native 1.3.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-23] Accepted tomcat-native 1.3.1-1 (source) into unstable (Emmanuel Bourg)
  • [2023-02-23] tomcat-native 1.2.35-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-12] Accepted tomcat-native 1.2.35-1 (source) into unstable (Markus Koschany)
  • [2022-05-08] tomcat-native 1.2.32-1 MIGRATED to testing (Debian testing watch)
  • [2022-05-02] Accepted tomcat-native 1.2.32-1 (source) into unstable (Emmanuel Bourg)
  • [2021-09-25] tomcat-native 1.2.31-1 MIGRATED to testing (Debian testing watch)
  • [2021-09-19] Accepted tomcat-native 1.2.31-1 (source) into unstable (Emmanuel Bourg)
  • [2021-01-16] Accepted tomcat-native 1.2.26-1~bpo10+1 (source) into buster-backports (Emmanuel Bourg)
  • [2021-01-11] tomcat-native 1.2.26-1 MIGRATED to testing (Debian testing watch)
  • [2021-01-05] Accepted tomcat-native 1.2.26-1 (source) into unstable (Emmanuel Bourg)
  • [2020-12-21] Accepted tomcat-native 1.2.25-1~bpo10+1 (source amd64) into buster-backports, buster-backports (Debian FTP Masters) (signed by: Emmanuel Bourg)
  • [2020-09-13] tomcat-native 1.2.25-1 MIGRATED to testing (Debian testing watch)
  • [2020-09-07] Accepted tomcat-native 1.2.25-1 (source) into unstable (Emmanuel Bourg)
  • [2020-06-06] tomcat-native 1.2.24-1 MIGRATED to testing (Debian testing watch)
  • [2020-05-31] Accepted tomcat-native 1.2.24-1 (source) into unstable (Emmanuel Bourg)
  • [2019-12-29] Accepted tomcat-native 1.2.21-1~deb9u1 (source amd64) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Markus Koschany)
  • [2019-12-27] Accepted tomcat-native 1.2.21-1~deb9u1 (source amd64) into oldstable->embargoed, oldstable (Markus Koschany)
  • [2019-07-17] tomcat-native 1.2.23-1 MIGRATED to testing (Debian testing watch)
  • [2019-07-11] Accepted tomcat-native 1.2.23-1 (source) into unstable (Emmanuel Bourg)
  • [2019-02-08] Accepted tomcat-native 1.2.21-1~bpo9+1 (source) into stretch-backports (Emmanuel Bourg)
  • [2019-02-06] tomcat-native 1.2.21-1 MIGRATED to testing (Debian testing watch)
  • [2019-01-31] Accepted tomcat-native 1.2.21-1 (source) into unstable (Emmanuel Bourg)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.0.15~us1-0ubuntu1
  • 2 bugs
  • patches for 2.0.15~us1-0ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing