Skip to content

Fix critical embedded Tomcat vulnerabilities - #37

Merged
arnabnandy7 merged 1 commit into
mainfrom
hotfix/vulnerabilityFix0.3
Sep 3, 2026
Merged

Fix critical embedded Tomcat vulnerabilities#37
arnabnandy7 merged 1 commit into
mainfrom
hotfix/vulnerabilityFix0.3

Conversation

@arnabnandy7

Copy link
Copy Markdown
Owner

Summary

  • upgrade embedded Tomcat components from 11.0.22 to 11.0.25
  • keep tomcat-embed-core, tomcat-embed-el, and tomcat-embed-websocket aligned

Security impact

Resolves the versions associated with Dependabot alerts #49, #50, and #51 after merge and dependency graph refresh:

Testing

  • mvn --batch-mode --no-transfer-progress clean test
  • Maven reactor: 6/6 modules successful
  • verified all embedded Tomcat components resolve to 11.0.25

@sonarqubecloud

sonarqubecloud Bot commented Sep 3, 2026

Copy link
Copy Markdown

@arnabnandy7
arnabnandy7 merged commit fd7a634 into main Sep 3, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant