ELSA-2026-68660

ELSA-2026-68660 - tomcat security, bug fix, and enhancement update

Type:SECURITY
Impact:MODERATE
Release Date:2026-09-17

Description


[1:9.0.120-1]
- Resolves: RHEL-192825 HTTP/2 request headers not validated (CVE-2026-41293)
- Resolves: RHEL-192659 Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990)
- Resolves: RHEL-219565 Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083)
- Resolves: RHEL-219573 Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084)
- Resolves: RHEL-238189 tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498)
- Resolves: RHEL-238247 tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513)
- Resolves: RHEL-238277 tomcat: Improper Authorization allows security bypass (CVE-2026-43515)
- Resolves: RHEL-238302 tomcat: Authentication bypass via digest authentication (CVE-2026-43512)
- Related: RHEL-183992 Remove tomcat clustering JAR from RPM builds

[1:9.0.110-1]
- Resolves: RHEL-148687
Update to 9.0.110 and compile with Java 25 to enable FFM features for PQC support

[1:9.0.87-7]
- Resolves: RHEL-124516
tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752)
- Resolves: RHEL-132561
tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651)

[1:9.0.87-6]
- Resolves: RHEL-102201
tomcat: http/2 'MadeYouReset' DoS attack through HTTP/2 control frames (CVE-2025-48989)

[1:9.0.87-5]
- Resolves: RHEL-108489
tomcat: Apache Commons FileUpload DOS via part headers (CVE-2025-48976)
- Resolves: RHEL-108497
tomcat: Dos in multipart upload (CVE-2025-48988)
- Resolves: RHEL-108505
tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)
- Resolves: RHEL-108513
tomcat: Denial of service (CVE-2025-52434)
- Resolves: RHEL-108529
tomcat: Denial of service (CVE-2025-52520)
- Resolves: RHEL-108523
tomcat: Denial of service (CVE-2025-53506)

[1:9.0.87-4]
- Resolves: RHEL-91763
tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)
- Resolves: RHEL-71985
tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)

[1:9.0.87-3]
- Resolves: RHEL-82945
tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT (CVE-2025-24813)
- Resolves: RHEL-71723
tomcat: RCE due to TOCTOU issue in JSP compilation (CVE-2024-50379)

[1:9.0.87-2]
- Resolves: RHEL-46163
tomcat: Improper Handling of Exceptional Conditions (CVE-2024-34750)
- Resolves: RHEL-18245 - OpenJDK 21 support for RHEL Tomcat


Related CVEs


CVE-2026-32990
CVE-2026-41293
CVE-2026-42498
CVE-2026-43512
CVE-2026-43513
CVE-2026-43515
CVE-2026-59083
CVE-2026-59084

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) tomcat-9.0.120-2.el9_8.src.rpm2c41a0a407a65976ea546a7eb2d7edb9f674132fc654ef8714fa6ca6de9b3171-ol9_aarch64_appstream
tomcat-9.0.120-2.el9_8.noarch.rpm59826f302db773c34befed8594f20cf51385cc65b5cb43dea68ef9fd3684b453-ol9_aarch64_appstream
tomcat-admin-webapps-9.0.120-2.el9_8.noarch.rpm922065d4158fcac1b5e06cc9b343526de0d6b7b1916e7ba30bc52d5d255d765f-ol9_aarch64_appstream
tomcat-docs-webapp-9.0.120-2.el9_8.noarch.rpm0b73fa4480def072e78ed0075f7e17c3e4c7f7e6ecb48f8856ed21197ced8436-ol9_aarch64_appstream
tomcat-el-3.0-api-9.0.120-2.el9_8.noarch.rpm832a54ec5a6f244cfb33625eb83e6a8faf1f89ee20750f43544c75189ed535ba-ol9_aarch64_appstream
tomcat-jsp-2.3-api-9.0.120-2.el9_8.noarch.rpm1ef9dad57df66b7c0168d5d492771052dce043fe699a792bdb90ece0366b28b3-ol9_aarch64_appstream
tomcat-lib-9.0.120-2.el9_8.noarch.rpm0b009f5c59d6fb480a920eb93b868c9c73778e5d96d9f5f40ab97a46efc11378-ol9_aarch64_appstream
tomcat-servlet-4.0-api-9.0.120-2.el9_8.noarch.rpm5c61796fdefb1e90966b9b59ddc180084527b2184403dceffa19faaf34cefbcb-ol9_aarch64_appstream
tomcat-webapps-9.0.120-2.el9_8.noarch.rpm4eee9e96a10b4e19de5bcb1dc51aa32d87b63ebc8459b6d675fc3f75a67c0c64-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) tomcat-9.0.120-2.el9_8.src.rpm2c41a0a407a65976ea546a7eb2d7edb9f674132fc654ef8714fa6ca6de9b3171-ol9_x86_64_appstream
tomcat-9.0.120-2.el9_8.noarch.rpm59826f302db773c34befed8594f20cf51385cc65b5cb43dea68ef9fd3684b453-ol9_x86_64_appstream
tomcat-admin-webapps-9.0.120-2.el9_8.noarch.rpm922065d4158fcac1b5e06cc9b343526de0d6b7b1916e7ba30bc52d5d255d765f-ol9_x86_64_appstream
tomcat-docs-webapp-9.0.120-2.el9_8.noarch.rpm0b73fa4480def072e78ed0075f7e17c3e4c7f7e6ecb48f8856ed21197ced8436-ol9_x86_64_appstream
tomcat-el-3.0-api-9.0.120-2.el9_8.noarch.rpm832a54ec5a6f244cfb33625eb83e6a8faf1f89ee20750f43544c75189ed535ba-ol9_x86_64_appstream
tomcat-jsp-2.3-api-9.0.120-2.el9_8.noarch.rpm1ef9dad57df66b7c0168d5d492771052dce043fe699a792bdb90ece0366b28b3-ol9_x86_64_appstream
tomcat-lib-9.0.120-2.el9_8.noarch.rpm0b009f5c59d6fb480a920eb93b868c9c73778e5d96d9f5f40ab97a46efc11378-ol9_x86_64_appstream
tomcat-servlet-4.0-api-9.0.120-2.el9_8.noarch.rpm5c61796fdefb1e90966b9b59ddc180084527b2184403dceffa19faaf34cefbcb-ol9_x86_64_appstream
tomcat-webapps-9.0.120-2.el9_8.noarch.rpm4eee9e96a10b4e19de5bcb1dc51aa32d87b63ebc8459b6d675fc3f75a67c0c64-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete