| Type: | SECURITY |
| Impact: | MODERATE |
| Release Date: | 2026-09-17 |
[1:9.0.120-1]
- Resolves: RHEL-192825 HTTP/2 request headers not validated (CVE-2026-41293)
- Resolves: RHEL-192659 Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990)
- Resolves: RHEL-219565 Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083)
- Resolves: RHEL-219573 Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084)
- Resolves: RHEL-238189 tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498)
- Resolves: RHEL-238247 tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513)
- Resolves: RHEL-238277 tomcat: Improper Authorization allows security bypass (CVE-2026-43515)
- Resolves: RHEL-238302 tomcat: Authentication bypass via digest authentication (CVE-2026-43512)
- Related: RHEL-183992 Remove tomcat clustering JAR from RPM builds
[1:9.0.110-1]
- Resolves: RHEL-148687
Update to 9.0.110 and compile with Java 25 to enable FFM features for PQC support
[1:9.0.87-7]
- Resolves: RHEL-124516
tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752)
- Resolves: RHEL-132561
tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651)
[1:9.0.87-6]
- Resolves: RHEL-102201
tomcat: http/2 'MadeYouReset' DoS attack through HTTP/2 control frames (CVE-2025-48989)
[1:9.0.87-5]
- Resolves: RHEL-108489
tomcat: Apache Commons FileUpload DOS via part headers (CVE-2025-48976)
- Resolves: RHEL-108497
tomcat: Dos in multipart upload (CVE-2025-48988)
- Resolves: RHEL-108505
tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)
- Resolves: RHEL-108513
tomcat: Denial of service (CVE-2025-52434)
- Resolves: RHEL-108529
tomcat: Denial of service (CVE-2025-52520)
- Resolves: RHEL-108523
tomcat: Denial of service (CVE-2025-53506)
[1:9.0.87-4]
- Resolves: RHEL-91763
tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)
- Resolves: RHEL-71985
tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)
[1:9.0.87-3]
- Resolves: RHEL-82945
tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT (CVE-2025-24813)
- Resolves: RHEL-71723
tomcat: RCE due to TOCTOU issue in JSP compilation (CVE-2024-50379)
[1:9.0.87-2]
- Resolves: RHEL-46163
tomcat: Improper Handling of Exceptional Conditions (CVE-2024-34750)
- Resolves: RHEL-18245 - OpenJDK 21 support for RHEL Tomcat
| CVE-2026-32990 |
| CVE-2026-41293 |
| CVE-2026-42498 |
| CVE-2026-43512 |
| CVE-2026-43513 |
| CVE-2026-43515 |
| CVE-2026-59083 |
| CVE-2026-59084 |
| Release/Architecture | Filename | sha256 | Superseded By Advisory | Channel Label |
| Oracle Linux 9 (aarch64) | tomcat-9.0.120-2.el9_8.src.rpm | 2c41a0a407a65976ea546a7eb2d7edb9f674132fc654ef8714fa6ca6de9b3171 | - | ol9_aarch64_appstream |
| tomcat-9.0.120-2.el9_8.noarch.rpm | 59826f302db773c34befed8594f20cf51385cc65b5cb43dea68ef9fd3684b453 | - | ol9_aarch64_appstream | |
| tomcat-admin-webapps-9.0.120-2.el9_8.noarch.rpm | 922065d4158fcac1b5e06cc9b343526de0d6b7b1916e7ba30bc52d5d255d765f | - | ol9_aarch64_appstream | |
| tomcat-docs-webapp-9.0.120-2.el9_8.noarch.rpm | 0b73fa4480def072e78ed0075f7e17c3e4c7f7e6ecb48f8856ed21197ced8436 | - | ol9_aarch64_appstream | |
| tomcat-el-3.0-api-9.0.120-2.el9_8.noarch.rpm | 832a54ec5a6f244cfb33625eb83e6a8faf1f89ee20750f43544c75189ed535ba | - | ol9_aarch64_appstream | |
| tomcat-jsp-2.3-api-9.0.120-2.el9_8.noarch.rpm | 1ef9dad57df66b7c0168d5d492771052dce043fe699a792bdb90ece0366b28b3 | - | ol9_aarch64_appstream | |
| tomcat-lib-9.0.120-2.el9_8.noarch.rpm | 0b009f5c59d6fb480a920eb93b868c9c73778e5d96d9f5f40ab97a46efc11378 | - | ol9_aarch64_appstream | |
| tomcat-servlet-4.0-api-9.0.120-2.el9_8.noarch.rpm | 5c61796fdefb1e90966b9b59ddc180084527b2184403dceffa19faaf34cefbcb | - | ol9_aarch64_appstream | |
| tomcat-webapps-9.0.120-2.el9_8.noarch.rpm | 4eee9e96a10b4e19de5bcb1dc51aa32d87b63ebc8459b6d675fc3f75a67c0c64 | - | ol9_aarch64_appstream | |
| Oracle Linux 9 (x86_64) | tomcat-9.0.120-2.el9_8.src.rpm | 2c41a0a407a65976ea546a7eb2d7edb9f674132fc654ef8714fa6ca6de9b3171 | - | ol9_x86_64_appstream |
| tomcat-9.0.120-2.el9_8.noarch.rpm | 59826f302db773c34befed8594f20cf51385cc65b5cb43dea68ef9fd3684b453 | - | ol9_x86_64_appstream | |
| tomcat-admin-webapps-9.0.120-2.el9_8.noarch.rpm | 922065d4158fcac1b5e06cc9b343526de0d6b7b1916e7ba30bc52d5d255d765f | - | ol9_x86_64_appstream | |
| tomcat-docs-webapp-9.0.120-2.el9_8.noarch.rpm | 0b73fa4480def072e78ed0075f7e17c3e4c7f7e6ecb48f8856ed21197ced8436 | - | ol9_x86_64_appstream | |
| tomcat-el-3.0-api-9.0.120-2.el9_8.noarch.rpm | 832a54ec5a6f244cfb33625eb83e6a8faf1f89ee20750f43544c75189ed535ba | - | ol9_x86_64_appstream | |
| tomcat-jsp-2.3-api-9.0.120-2.el9_8.noarch.rpm | 1ef9dad57df66b7c0168d5d492771052dce043fe699a792bdb90ece0366b28b3 | - | ol9_x86_64_appstream | |
| tomcat-lib-9.0.120-2.el9_8.noarch.rpm | 0b009f5c59d6fb480a920eb93b868c9c73778e5d96d9f5f40ab97a46efc11378 | - | ol9_x86_64_appstream | |
| tomcat-servlet-4.0-api-9.0.120-2.el9_8.noarch.rpm | 5c61796fdefb1e90966b9b59ddc180084527b2184403dceffa19faaf34cefbcb | - | ol9_x86_64_appstream | |
| tomcat-webapps-9.0.120-2.el9_8.noarch.rpm | 4eee9e96a10b4e19de5bcb1dc51aa32d87b63ebc8459b6d675fc3f75a67c0c64 | - | ol9_x86_64_appstream | |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team