From 75d0db4292df1c6bfda159cf5d01d13011223125 Mon Sep 17 00:00:00 2001 From: Yuki FUJITA Date: Tue, 28 Apr 2026 16:16:24 +0900 Subject: [PATCH] Improve GHSA-563x-q5rq-57qp --- .../GHSA-563x-q5rq-57qp.json | 72 +++++++++++++++++-- 1 file changed, 66 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2026/04/GHSA-563x-q5rq-57qp/GHSA-563x-q5rq-57qp.json b/advisories/github-reviewed/2026/04/GHSA-563x-q5rq-57qp/GHSA-563x-q5rq-57qp.json index eac1b5f717f4c..22655f240dddc 100644 --- a/advisories/github-reviewed/2026/04/GHSA-563x-q5rq-57qp/GHSA-563x-q5rq-57qp.json +++ b/advisories/github-reviewed/2026/04/GHSA-563x-q5rq-57qp/GHSA-563x-q5rq-57qp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-563x-q5rq-57qp", - "modified": "2026-04-15T22:39:21Z", + "modified": "2026-04-15T22:39:22Z", "published": "2026-04-09T21:31:29Z", "aliases": [ "CVE-2026-24880" @@ -18,7 +18,7 @@ { "package": { "ecosystem": "Maven", - "name": "org.apache.tomcat:tomcat-tribes" + "name": "org.apache.tomcat:tomcat" }, "ranges": [ { @@ -37,7 +37,7 @@ { "package": { "ecosystem": "Maven", - "name": "org.apache.tomcat:tomcat-tribes" + "name": "org.apache.tomcat:tomcat" }, "ranges": [ { @@ -56,7 +56,45 @@ { "package": { "ecosystem": "Maven", - "name": "org.apache.tomcat:tomcat-tribes" + "name": "org.apache.tomcat:tomcat-coyote" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.0.0" + }, + { + "fixed": "9.0.116" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.tomcat:tomcat-coyote" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.1.0-M1" + }, + { + "fixed": "10.1.52" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.tomcat:tomcat-coyote" }, "ranges": [ { @@ -80,6 +118,28 @@ "ecosystem": "Maven", "name": "org.apache.tomcat:tomcat" }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "11.0.0-M1" + }, + { + "fixed": "11.0.20" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 11.0.18" + } + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.tomcat.embed:tomcat-embed-core" + }, "ranges": [ { "type": "ECOSYSTEM", @@ -97,7 +157,7 @@ { "package": { "ecosystem": "Maven", - "name": "org.apache.tomcat:tomcat" + "name": "org.apache.tomcat.embed:tomcat-embed-core" }, "ranges": [ { @@ -116,7 +176,7 @@ { "package": { "ecosystem": "Maven", - "name": "org.apache.tomcat:tomcat" + "name": "org.apache.tomcat.embed:tomcat-embed-core" }, "ranges": [ {