SShortSingh.
Back to feed

Patch Matrix for CVE-2026-86350: Which Apache Tomcat Builds Need 11.0.26, 10.1.60 or 9.0.122

0
·3 views

Patch Matrix for CVE-2026-86350: Which Apache Tomcat Builds Need 11.0.26, 10.1.60 or 9.0.122 Operator summary CVE-2026-86350 is an Important-severity Apache Tomcat defect involving a request header mix-up in HTTP/2 handling. It is a regression from the fix for CVE-2026-41293. Remediation is a version move, and the correct target depends on the branch a server runs. Branch Vulnerable range Fixed release Vendor commit Tomcat 11.0.x 11.0.22 to 11.0.25 11.0.26 192bc749 Tomcat 10.1.x 10.1.55 to 10.1.59 10.1.60 259e938d Tomcat 9.0.x 9.0.118 to 9.0.121 9.0.122 5adadc4e Tomcat 8.5 does not appear agai

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Why Small Developer Tools Can Have a Big Impact

Why Small Developer Tools Can Have a Big Impact When developers think about building software, it is easy to imagine large applications with authentication, dashboards, databases, APIs, AI features, and dozens of screens. But some of the most useful software can be surprisingly small. A command-line utility that saves five minutes every day can become more valuable than a huge application that users rarely open. A good small tool usually starts with an irritating problem. Maybe you repeatedly need to: Rename hundreds of files Convert data between formats Find duplicate files Check a project's

0
ProgrammingDEV Community ·

I gave my YC jobs scraper write access to Notion without ever holding a Notion token

TL;DR Apify MCP connectors use the Model Context Protocol (MCP) to let an Actor write into a user's connected apps without ever touching that app's credentials. I used one to push my scraped Y Combinator jobs straight into Notion and delete my CSV export step. Below: why a token field was never an option for a published Actor, the documented Python snippet that couldn't run on any SDK version, and five steps covering connector setup, tool discovery, field mapping, safe writes, and what the whole thing costs per run. My Y Combinator jobs scraper has run happily for months. It walks the YC direc

0
ProgrammingDEV Community ·

Go SQL Query Builder Without Dependencies: Relica, the ozzo-dbx Successor — What Broke on PostgreSQL and SQLite

Relica is a zero-dependency SQL query builder for Go (PostgreSQL, MySQL, SQLite), the successor to ozzo-dbx. I wrote it from scratch, keeping the API design of ozzo-dbx — the query builder by Qiang Xue, creator of Yii framework. Qiang hadn't maintained it for years, and when he handed me the go-ozzo organization in mid-2026, Relica was already in production. We run Relica in production across multiple services on PostgreSQL, MySQL and SQLite, and an external code auditor recently found six critical bugs in one session. This article is about those bugs, how they got there, and the patterns that

0
ProgrammingDEV Community ·

A small JSON handoff for a custom figurine from a photo

A rendered preview and a printable model answer different questions. The preview communicates appearance; the production file must also match an agreed size, material and version. If those facts live only in a chat, it is easy to lose track of which revision a customer actually approved. Here is a lightweight data model for keeping that handoff explicit. This is an illustrative design proposal, not a claim about Formacara's deployed software.