-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 3 Feb 2026 14:04:48 CET Source: tomcat10 Architecture: source Version: 10.1.52-1~deb13u1 Distribution: trixie-security Urgency: medium Maintainer: Debian Java Maintainers Changed-By: Markus Koschany Checksums-Sha1: d517757b1b9b702e00833844bb23046a6c405870 3069 tomcat10_10.1.52-1~deb13u1.dsc 2e1309f9ae2114ff28293bc0f7a877360d529984 4952520 tomcat10_10.1.52.orig.tar.xz 77f2498ec88ec2d0bd6991f8e2306a07234f0b68 37784 tomcat10_10.1.52-1~deb13u1.debian.tar.xz 505dc8103ac96fa45f9bb0c77c2c755f9f58ab7b 17294 tomcat10_10.1.52-1~deb13u1_amd64.buildinfo Checksums-Sha256: d4d7c1db68531511a9b3f928c217574557b09b43f346581e64db3840b39a39bc 3069 tomcat10_10.1.52-1~deb13u1.dsc 34218636f749ab70d6074dc7ba7b1b7128b6ab8626b28a76f5a034f975689ac2 4952520 tomcat10_10.1.52.orig.tar.xz 984a1f29004f891a543d6483a6c3df8d0022b57fcfd605c6602750061350b30d 37784 tomcat10_10.1.52-1~deb13u1.debian.tar.xz bf08cb42470c9b0fb20939eff1e74150e425c36baca993e626f796334ded4864 17294 tomcat10_10.1.52-1~deb13u1_amd64.buildinfo Changes: tomcat10 (10.1.52-1~deb13u1) trixie-security; urgency=medium . * Backport 10.1.52. to trixie. * Fix CVE-2025-46701, CVE-2025-48976, CVE-2025-48988, CVE-2025-48989, CVE-2025-49125, CVE-2025-52520, CVE-2025-53506, CVE-2025-55668, CVE-2025-55752, CVE-2025-55754 and CVE-2025-61795. Several security vulnerabilities have been found in Tomcat 10, a Java web server and servlet engine. This update improves the handling of HTTP/2 connections and corrects various flaws which can lead to uncontrolled resource consumption and a denial of service. Files: 076c52ae080b33b09d5f04dc4e069813 3069 java optional tomcat10_10.1.52-1~deb13u1.dsc 7cd90ce5ac465d0819471b7ce6295ec0 4952520 java optional tomcat10_10.1.52.orig.tar.xz 094334c001408b72295c59da0f7287d0 37784 java optional tomcat10_10.1.52-1~deb13u1.debian.tar.xz a70e7b1df895f192bb4b0a2d01c3576a 17294 java optional tomcat10_10.1.52-1~deb13u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmmB8q5fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkeLYP/j0RxaQHzGDe7O1eklXxrBYnqKFTcRJVs6pi OeqMzFcA8d9INhFt1E8RKAL9mE4SuwmmD9WuTfFdCTALF4T4/dy7drFpfjVPk7h9 S5B2FzQkMVCJbrrsu65AqfjHSZMf8TDLF0EsqZxELefwL8nkGrhyAJ36oBzdES1J o5XAHY11k26a3K0mWj5Fggt9rFeMkdsW4c8MnBCYBDs4jfunhGgoDoez6RFyXSla jvy6iRS4Xih8MOzRPHcpxKW6ZvoYclYMEH2K9AGe6AN7OLEX08r21RtWsm/jcRAU jiIln5lVfL6s6FjWTBiX98TfizxhCmXULmL/lypix/2ieTdAZUmUEP1Ip/Sc46at FNViakXvUWGxusFEA5X4xUA28V2hInA/otXKnOPEx8U2FoOWephvbac9R67L/4mt P/0O+EAlrc7pgKCyqjd/oiFgnHG8xQpRn1+ZRn1K9Dt6J9yuz3GBES+RkhVlSyt8 OAEY3lW2nIjizJrG+AVxF6BtocBQF9OXzWHr6zk/beEgiuUNDWJdFgafw7G3Uue1 HfB4lvdqZy9xqlf1wa93IpJ87IUkZagpJBL9pQz0QcXjpLNi89PeJ7C+g0wxLn4I DEvHndKlG8io4GWsmveSv5ni6dSKczWpCuQrXF7nSb9izkge65l6253K7GgE/MKr BZCm2/sx =iEb9 -----END PGP SIGNATURE-----