RHSA-2026:68659HighCVSS 7.5

Red Hat Security Advisory: tomcat security update

Published
September 17, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (30)

📋 Description

CVE-2024-52316 — tomcat: Apache Tomcat: Authentication bypass when using Jakarta Authentication API CVE-2024-54677 — tomcat: Apache Tomcat: DoS in examples web application CVE-2025-46701 — tomcat: Apache Tomcat: Security constraint bypass for CGI scripts CVE-2025-55668 — org.apache.tomcat/tomcat-catalina: tomcat: Apache Tomcat: session fixation via rewrite valve CVE-2025-55754 — org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation CVE-2025-61795 — tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Denial of service CVE-2025-66614 — tomcat: Client certificate verification bypass due to virtual host mapping CVE-2026-24733 — tomcat: security constraint bypass with HTTP/0.9 CVE-2026-24880 — Apache Tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension CVE-2026-25854 — Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve CVE-2026-29145 — Apache Tomcat: Apache Tomcat: Authentication bypass due to CLIENT_CERT soft fail misconfiguration CVE-2026-32990 — Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix CVE-2026-34483 — Apache Tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve CVE-2026-34487 — Apache Tomcat: Apache Tomcat: Information disclosure via sensitive data in log files CVE-2026-41284 — tomcat: Apache Tomcat: Denial of Service due to uncontrolled resource allocation CVE-2026-41293 — tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated CVE-2026-42498 — tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. CVE-2026-43512 — tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication CVE-2026-43513 — tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm CVE-2026-43514 — tomcat: Apache Tomcat: Information disclosure via AJP secret timing discrepancy CVE-2026-43515 — tomcat-coyote: tomcat: Improper Authorization allows security bypass CVE-2026-50229 — tomcat: Apache Tomcat: Cross-Site Scripting vulnerability in number guess example CVE-2026-53404 — Apache Tomcat: Apache Tomcat: Incorrect control flow in rewrite valve allows unexpected rule processing CVE-2026-53434 — tomcat: Apache Tomcat: Error condition not handled when configuring CRLs CVE-2026-55276 — tomcat: Apache Tomcat: Misleading security logs due to incorrect control flow CVE-2026-55955 — tomcat: Apache Tomcat: Replay attack via improper authentication in EncryptionInterceptor CVE-2026-55956 — tomcat: Apache Tomcat: Improper Authorization Allows Security Constraint Bypass CVE-2026-55957 — tomcat: Apache Tomcat: Authentication bypass via missing critical step in JNDIRealm GSSAPI configuration CVE-2026-59083 — tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve CVE-2026-59084 — tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations

🎯 Affected products10

  • Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • tomcat-1:9.0.120-1.el9_6.noarch as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • tomcat-1:9.0.120-1.el9_6.src as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • tomcat-admin-webapps-1:9.0.120-1.el9_6.noarch as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • tomcat-docs-webapp-1:9.0.120-1.el9_6.noarch as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • tomcat-el-3.0-api-1:9.0.120-1.el9_6.noarch as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • tomcat-jsp-2.3-api-1:9.0.120-1.el9_6.noarch as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • tomcat-lib-1:9.0.120-1.el9_6.noarch as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • tomcat-servlet-4.0-api-1:9.0.120-1.el9_6.noarch as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • tomcat-webapps-1:9.0.120-1.el9_6.noarch as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, ensure that security constraints are consistent across similar methods (e.g., if GET is denied, HEAD should likely be denied) or block HTTP/0.9 traffic via a reverse proxy or firewall, if it is not required. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, disable or remove the LoadBalancerDrainingValve configuration from the server.xml file in your Apache Tomcat installation. This valve is typically configured within a <Host> or <Engine> element. After modifying server.xml, restart the Apache Tomcat service for the changes to take effect. This action may impact load balancing functionality if the valve is actively used for draining connections. Workaround: To mitigate this issue, ensure that CLIENT_CERT authentication is configured to strictly enforce client certificate validation. Review the Apache Tomcat conf/server.xml configuration. For SSLHostConfig or Connector elements, set the clientAuth attribute to required or ensure softFail is enabled if optional client certificate authentication is desired. A restart of the Apache Tomcat service is necessary for these configuration changes to apply. Workaround: Disable the cloud membership for clustering feature in Apache Tomcat if it is not actively used. Additionally, ensure that access to Apache Tomcat log files is strictly controlled and limited to authorized personnel only to prevent unauthorized disclosure of sensitive information. If the cloud membership for clustering feature is disabled, a restart of the Apache Tomcat service may be required for the changes to take effect. Workaround: To mitigate this issue, disable DIGEST authentication within Apache Tomcat if it is not essential for your environment. This involves modifying the server's authentication configuration to utilize alternative methods or remove the DIGEST realm. A service restart is required for these changes to take effect and may impact functionality relying on DIGEST authentication. Workaround: This vulnerability only affects Tomcat deployments using the LockOutRealm with a case-insensitive authentication backend. Deployments not using LockOutRealm or using case-sensitive authentication backends are not affected. Workaround: Remove or disable the Tomcat example web applications if they are deployed. Example applications are not needed for production use and should not be accessible in production environments. Workaround: This vulnerability only affects Tomcat deployments that use the RewriteValve with OR-chained rewrite conditions. Deployments that do not use the RewriteValve are not affected. Review rewrite rules for OR-chained conditions and test rule evaluation behavior. Workaround: This vulnerability only affects Tomcat deployments using the FFM-based connector (requires Java 22+) with CRL-based certificate revocation checking. Deployments using the standard NIO/NIO2 connectors or not using CRL checking are not affected. Workaround: This is a logging-only issue with no runtime security impact. No mitigation is required. Administrators should not rely solely on the effective web.xml debug log output to verify security constraint configuration. Workaround: This vulnerability only affects Tomcat deployments using the EncryptionInterceptor for Tribes cluster communication. Deployments that do not use Tomcat clustering or do not configure the EncryptionInterceptor are not affected. Ensure cluster communication channels are restricted to trusted, isolated networks. Workaround: Review your application's web.xml file. Ensure security constraints explicitly deny unauthorized users by path, rather than relying strictly on filtering specific HTTP methods (like GET or POST). Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this issue, review Apache Tomcat's rewrite valve configurations. If the rewrite valve is not essential for your application, consider disabling it. If it is required, ensure its configuration does not permit improper URL encoding that could lead to security constraint bypasses. A service restart may be required for changes to take effect. Workaround: To mitigate this issue, ensure that the EncryptInterceptor in Apache Tomcat is configured according to secure best practices. Review existing configurations of EncryptInterceptor to verify that all security requirements are met and that no insecure settings are in place. If the EncryptInterceptor is not actively used, no specific action is required.

🔗 References (12)