[ALSA-2026:68660] Moderate: tomcat security, bug fix, and enhancement update
Type:
security
Severity:
moderate
Release date:
2026-09-18
Description:
Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990) * tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512) * tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293) * tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. (CVE-2026-42498) * tomcat-coyote: tomcat: Improper Authorization allows security bypass (CVE-2026-43515) * tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) * tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) * tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084) Bug Fix(es) and Enhancement(s): * Tomcat fails to respond to client connections when using Java 8 [almalinux-9.8] (JIRA:AlmaLinux-257456) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch tomcat-docs-webapp-9.0.120-2.el9_8.noarch.rpm 6dfc559a43177a819c06487fa6024ce010776c6b5e89381af229eb5fc7aa5c67
noarch tomcat-admin-webapps-9.0.120-2.el9_8.noarch.rpm 75578cde5feced53de7864e3f3a5ebbc277a2f27bce1aa5898a0b3f5af0b0daf
noarch tomcat-el-3.0-api-9.0.120-2.el9_8.noarch.rpm 9a379f7274681c05c662801d6ba3485760cd41eb494ffdfad7f2c63efcc2edd3
noarch tomcat-jsp-2.3-api-9.0.120-2.el9_8.noarch.rpm bc687b69d033983fc9896992f2334962a6b3637f01d6920e9199c39b38abf192
noarch tomcat-servlet-4.0-api-9.0.120-2.el9_8.noarch.rpm be94b701599d2a1c328fabc0a744a4947ba3af4d7affbf0c838b81dd1e299b68
noarch tomcat-9.0.120-2.el9_8.noarch.rpm c0bca291238df35d1177e1069f1e00b400684ea0cef283d1cf2ed9634852fa93
noarch tomcat-lib-9.0.120-2.el9_8.noarch.rpm d657d0abbb1d15d592b39a564ae6065edfe97aed367809d4685bc0c968cfba40
noarch tomcat-webapps-9.0.120-2.el9_8.noarch.rpm e55f968b0ef13f637323c703d64ca51bd1d4a72f4b9b284dabe683300dbd0287
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.