[GHSA-fccv-jmmp-qg76] Apache Tomcat Improper Input Validation vulnerability#7662
[GHSA-fccv-jmmp-qg76] Apache Tomcat Improper Input Validation vulnerability#7662aruneko wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Pull request overview
Updates the OSV advisory for GHSA-fccv-jmmp-qg76 (Apache Tomcat improper input validation / request smuggling risk) by expanding the set of affected Maven artifacts and their vulnerable version ranges.
Changes:
- Added
org.apache.tomcat:tomcat-coyoteas an affected Maven package across the relevant vulnerable/fixed version lines. - Added
org.apache.tomcat:tomcatas an affected Maven package across the relevant vulnerable/fixed version lines. - Bumped the advisory
modifiedtimestamp (but it remains in 2025).
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| "schema_version": "1.4.0", | ||
| "id": "GHSA-fccv-jmmp-qg76", | ||
| "modified": "2025-08-08T18:32:42Z", | ||
| "modified": "2025-08-08T18:32:43Z", |
|
👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the |
|
How is the status of a review for this pull request? |
|
Can you explain how you determined that org.apache.tomcat:tomcat-coyote is affected? |
|
In this commit, tomcat fixed the vulnerability. The commit includes the files |
Updates
Comments
improve affected packages