An update is available for tomcat. This update affects Rocky Linux 10. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
tomcat-1:10.1.36-3.el10_1.1.noarch.rpm
tomcat-1:10.1.36-3.el10_1.1.src.rpm
tomcat-admin-webapps-1:10.1.36-3.el10_1.1.noarch.rpm
tomcat-docs-webapp-1:10.1.36-3.el10_1.1.noarch.rpm
tomcat-el-5.0-api-1:10.1.36-3.el10_1.1.noarch.rpm
tomcat-jsp-3.1-api-1:10.1.36-3.el10_1.1.noarch.rpm
tomcat-lib-1:10.1.36-3.el10_1.1.noarch.rpm
tomcat-servlet-6.0-api-1:10.1.36-3.el10_1.1.noarch.rpm
tomcat-webapps-1:10.1.36-3.el10_1.1.noarch.rpm
No references
https://www.cve.org/CVERecord?id=CVE-2025-31651
https://www.cve.org/CVERecord?id=CVE-2025-55752
https://www.cve.org/CVERecord?id=CVE-2025-61795
https://bugzilla.redhat.com/show_bug.cgi?id=2362782
https://bugzilla.redhat.com/show_bug.cgi?id=2406588
https://bugzilla.redhat.com/show_bug.cgi?id=2406591
Get the latest Linux and open source security news straight to your inbox.