-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 3 Feb 2026 13:20:26 CET Source: tomcat11 Architecture: source Version: 11.0.15-1~deb13u1 Distribution: trixie-security Urgency: medium Maintainer: Debian Java Maintainers Changed-By: Markus Koschany Checksums-Sha1: 3bbccbafe36deb83243098d60a21bcb5693f01e4 3081 tomcat11_11.0.15-1~deb13u1.dsc 1bdb16a58b8f4e3a72d67dacc0628407207ab62a 4905032 tomcat11_11.0.15.orig.tar.xz d2cd42d7fb4fc09cff17cddf77b91461e59590c2 33856 tomcat11_11.0.15-1~deb13u1.debian.tar.xz 56c74db452aae73c885c2d9e5acd39d3b3551353 17294 tomcat11_11.0.15-1~deb13u1_amd64.buildinfo Checksums-Sha256: 58e7d2cc83b34a54bf2e402a783c24f8ab6a60fc8057c39c6ac071001fac8b30 3081 tomcat11_11.0.15-1~deb13u1.dsc 81f9ac11187867fb704a73634e1326d32eb73ab75deff0d7c03075bf593cc97a 4905032 tomcat11_11.0.15.orig.tar.xz 15c051aa421271771b62f0f9f343d56726bbbe68a3e50b717db507ece7b2f695 33856 tomcat11_11.0.15-1~deb13u1.debian.tar.xz b752534374d799c8b8a994591ec18dab311ff02e1dae88c215fa7cf58cc98094 17294 tomcat11_11.0.15-1~deb13u1_amd64.buildinfo Changes: tomcat11 (11.0.15-1~deb13u1) trixie-security; urgency=medium . * Backport 11.0.15. to trixie. * Fix CVE-2025-46701, CVE-2025-48976, CVE-2025-48988, CVE-2025-48989, CVE-2025-49125, CVE-2025-52520, CVE-2025-53506, CVE-2025-55668, CVE-2025-55752, CVE-2025-55754 and CVE-2025-61795. Several security vulnerabilities have been found in Tomcat 11, a Java web server and servlet engine. This update improves the handling of HTTP/2 connections and corrects various flaws which can lead to uncontrolled resource consumption and a denial of service. Files: 3a6f0a6218a5b98bff76568e65ccfc94 3081 java optional tomcat11_11.0.15-1~deb13u1.dsc 9df78b26d9e96a804fa29206551209c3 4905032 java optional tomcat11_11.0.15.orig.tar.xz 54517d1a2550b4899dbb865f8e4b3790 33856 java optional tomcat11_11.0.15-1~deb13u1.debian.tar.xz 095f5cc05377d4407d167326a23713a5 17294 java optional tomcat11_11.0.15-1~deb13u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmmB6EhfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkyLoP/1WLmpEpCUUMtc7tCQczsiz647RaPDUgMTqM ytsQKIzcsau3xXZ990re7MpDogtKEZDsDTmfROaWWE6wJTCw/jlmiSi0o/+bG981 fNlxW0bUFFnSrkCJ71MBoytaxQq67PIXVRVQ3uao9mJOhxdQxERYtZj36cgx+Pbj /9VZDXeqOZdSs3M17eBwnjYaF8qGVANffMd7Ily9hZKeO8d4Oox/EIoa2EZcN5BL DZ0216MUoiCKXLCErwLjujtdBW5NGaqWKj9AzNPFTG9Y49OY66vZd/+Yxg1FLLgf 5BpizRHKjoWhJddYPg8mGf6sY6cV9PQ4CMgasZ3CzcsZS38BM2tveB9rfJLzzwn0 Xb0xUIP6LRQtPsmTltJIWeQRv1uUPVcyKsTPjb+rsjqtqn5xNx7Y+Wn8mCICvM8S iTukDi71rFzEJxhD64f3WBpMxeTkvW5gySx+yjjqIAhaB/b2W7ogdmayGyvWHFvt cn75I0uMNr0lgPfFk2R/Qj5/X3/9aoCI4BPlge3ytOnvHhQWNog+G9wLzFdmaD12 +SZWJ9EmMrp8plxv3l0GXpqxSnmQZrucRZLz4a+H3uqqruc76g2SbEOh0mQnqoG7 BdR5guc4YFHoPO5ZkbPlW38Qs8MmnpPRtXYiFEwBnScAAI55oenvdBm8akpoMRll ixwK3vuB =l9c/ -----END PGP SIGNATURE-----