[ALSA-2026:68677] Important: tomcat security update
Type:
security
Severity:
important
Release date:
2026-09-18
Description:
Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512) * tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293) * tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. (CVE-2026-42498) * tomcat-coyote: tomcat: Improper Authorization allows security bypass (CVE-2026-43515) * tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) * tomcat: Apache Tomcat: Authentication bypass via missing critical step in JNDIRealm GSSAPI configuration (CVE-2026-55957) * tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) * tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch tomcat-docs-webapp-9.0.120-1.el8_10.noarch.rpm 0d4f237f7d9589e691ba8c8f1d8f3aa631fed8a4a6bf27a21550305591d251f9
noarch tomcat-9.0.120-1.el8_10.noarch.rpm 0f0bc3d0525990b1579b67b437da066295dfe093420e0e969d313e1e30f121e2
noarch tomcat-lib-9.0.120-1.el8_10.noarch.rpm 5568530aa93119ca7ecca247bd3508ad01c8290910c39490bc65ff30d61e2b75
noarch tomcat-admin-webapps-9.0.120-1.el8_10.noarch.rpm 5c9a28eb70d25d912c98f0d259681b6faf23cc9d784bddda799b85b145e77159
noarch tomcat-servlet-4.0-api-9.0.120-1.el8_10.noarch.rpm 660133a56552b79267aa081813f5724cc6c1c62c767e86deb94ddcedb98d7c06
noarch tomcat-webapps-9.0.120-1.el8_10.noarch.rpm 6994af0f4e99a7dc2b1e4f8edca05cf9c60a18223f8b2a4d31df8ba8e0cf9bea
noarch tomcat-jsp-2.3-api-9.0.120-1.el8_10.noarch.rpm 9773bbbb3957a8745937d91cbbe041bda7ab9102e1d06e35dbe28d2e0fb69be2
noarch tomcat-el-3.0-api-9.0.120-1.el8_10.noarch.rpm c4d0784943b6d032244b8ea1077d5c72d7703dfa2460f3334e6e539eaa945d6c
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.