Skip to content

[GHSA-pxwv-88pv-hh3j] org/apache/tomcat/util/net/NioEndpoint.java in Apache Tom... - #10173

Draft
oscerd wants to merge 1 commit into
github:oscerd/advisory-improvement-10173from
oscerd:oscerd-GHSA-pxwv-88pv-hh3j
Draft

oscerd wants to merge 1 commit into
github:oscerd/advisory-improvement-10173from
oscerd:oscerd-GHSA-pxwv-88pv-hh3j

Conversation

@oscerd

@oscerd oscerd commented Oct 4, 2026

Copy link
Copy Markdown

[GHSA-pxwv-88pv-hh3j] org/apache/tomcat/util/net/NioEndpoint.java in Apache Tom...

Updates

  • Affected products
  • Source code location

Comments
Affected packages and version range are taken from the advisory text itself, which names the source file and the exact bound.

NioEndpoint lives in tomcat-coyote (and in the shaded tomcat-embed-core). The advisory also names "6.x before 6.0.36", but no Tomcat 6.x artifact is published on Maven Central (the oldest published versions are 7.0.0), so only the 7.x stream is encoded.

This is an old CVE (NVD backfilled it into the advisory database in 2022) on a Tomcat line that is long out of support, so the practical audience is small — but the range is unambiguous and every version in it is published on Maven Central, so the entry is exact.

Claude Code on behalf of oscerd

🤖 Generated with Claude Code

…Apache Tom...

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
@github-actions
github-actions Bot changed the base branch from main to oscerd/advisory-improvement-10173 October 4, 2026 11:17
@taladrane

Copy link
Copy Markdown
Collaborator

👋 @oscerd please refrain from opening additional PRs, even as drafts. We are unable to get to these as quickly as you're opening them, and opening them as a draft actively goes around the guards we have in place for this reason and delays further delays to those requests.

@oscerd

oscerd commented Oct 6, 2026

Copy link
Copy Markdown
Author

Sure thing. Do you want me to close all the drafts? I am just trying to sync the database. But I can wait for opened to get merged and only stay under the limit without draft just let me know

@oscerd

oscerd commented Oct 6, 2026

Copy link
Copy Markdown
Author

Thanks and sorry if it was a problem

@oscerd

oscerd commented Oct 6, 2026

Copy link
Copy Markdown
Author

Just let me know @taladrane

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants