[ALSA-2026:69259] Moderate: tomcat update
Type:
security
Severity:
moderate
Release date:
2026-09-22
Description:
Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990) * tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512) * tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293) * tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498) * tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) * tomcat-coyote: tomcat: Improper Authorization allows security bypass (CVE-2026-43515) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch tomcat-10.1.49-4.el10_2.alma.1.noarch.rpm 05f66cc8b41b005142502d651ba514eded6e74fadebc4bdc6c0d92950d6879df
noarch tomcat-lib-10.1.49-4.el10_2.alma.1.noarch.rpm 1ef407ca747b0004e12dfb23f976be66e723a1e587ab0958cba13bdb751f2505
noarch tomcat-webapps-10.1.49-4.el10_2.alma.1.noarch.rpm 3039facea1830d6007abf1fdc9482c06d32fcb2fb13da8d1c71963066f81e351
noarch tomcat-servlet-6.0-api-10.1.49-4.el10_2.alma.1.noarch.rpm 3b705c8b7203a1082a75a9137b187f792afaaf227daf36911e2dbeccf5e0f1b1
noarch tomcat-el-5.0-api-10.1.49-4.el10_2.alma.1.noarch.rpm 4df179b81ca2db0f43fec568ccc75a8679fffe363fec2fb6561e4f02955b8ae7
noarch tomcat-admin-webapps-10.1.49-4.el10_2.alma.1.noarch.rpm 7c7acfc2c6790f4c32d6cdaf0b0ebdfa664f793a282af54ec03f3852621bb52f
noarch tomcat-jsp-3.1-api-10.1.49-4.el10_2.alma.1.noarch.rpm a6fc4fb2bc554f7fe792d34fef93212e54a6708c02ec0a9ef3f40adf76158df1
noarch tomcat-docs-webapp-10.1.49-4.el10_2.alma.1.noarch.rpm d77aa50850c7291ba9872ee696549bcb39f63510d6dcf156bfa5d47ae3113c12
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.