[ALSA-2026:68651] Moderate: tomcat9 security update
Type:
security
Severity:
moderate
Release date:
2026-09-18
Description:
Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. Security Fix(es): * Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990) * tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512) * tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293) * tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. (CVE-2026-42498) * tomcat-coyote: tomcat: Improper Authorization allows security bypass (CVE-2026-43515) * tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) * tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) * tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch tomcat9-jsp-2.3-api-9.0.120-1.el10_2.alma.1.noarch.rpm 079235eb90790724bd53fa760599c4fabc2ca146f0df04dc03b825473f6929f0
noarch tomcat9-el-3.0-api-9.0.120-1.el10_2.alma.1.noarch.rpm 127036aa147028de0c591c915f5913b3c80dbbbb60b91558081f3842befb9deb
noarch tomcat9-9.0.120-1.el10_2.alma.1.noarch.rpm 4345bedf4762f697d7820e4c40e33db6d512fbb7bb3aa1bb1736a9517eb26bb1
noarch tomcat9-webapps-9.0.120-1.el10_2.alma.1.noarch.rpm 5438a76184cee45e329a47afa3263e09dfcd6150cbd0ff81c9aa64f29718fbaf
noarch tomcat9-admin-webapps-9.0.120-1.el10_2.alma.1.noarch.rpm 5abf8cce64844d9b8d793f656ee9059ff88d5778b36b2132610327becea70b50
noarch tomcat9-docs-webapp-9.0.120-1.el10_2.alma.1.noarch.rpm 8f39945c344abb46ae48edaeeb08c9422248d21b0fa78a5168faae09fb3f81ef
noarch tomcat9-lib-9.0.120-1.el10_2.alma.1.noarch.rpm c47704f2da56adf112c8a1acc1d7fe27bb3e7896bbfcbcdff7dcc0673fda1877
noarch tomcat9-servlet-4.0-api-9.0.120-1.el10_2.alma.1.noarch.rpm ddabae1dd27c35dd4cee5c1eae2a7f3dd9d8d1aa22810be1c19a7df07b7d56ed
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.