ELSA-2026-68677

ELSA-2026-68677 - tomcat security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-09-17

Description


[1:9.0.120-1]
- Resolves: RHEL-192806 HTTP/2 request headers not validated (CVE-2026-41293)
- Resolves: RHEL-219561 Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083)
- Resolves: RHEL-219581 Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084)
- Resolves: RHEL-238206 tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498)
- Resolves: RHEL-238213 tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513)
- Resolves: RHEL-238260 tomcat: Improper Authorization allows security bypass (CVE-2026-43515)
- Resolves: RHEL-238294 tomcat: Authentication bypass via digest authentication (CVE-2026-43512)
- Resolves: RHEL-239018 tomcat: Apache Tomcat: Authentication bypass via missing critical step in JNDIRealm GSSAPI configuration (CVE-2026-55957)


Related CVEs


CVE-2026-41293
CVE-2026-42498
CVE-2026-43512
CVE-2026-43513
CVE-2026-43515
CVE-2026-55957
CVE-2026-59083
CVE-2026-59084

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) tomcat-9.0.120-1.el8_10.src.rpmd6ec126c6671f79e3692787f805453be6373435bfb28231f9d7e69949aa2e1d7-ol8_aarch64_appstream
tomcat-9.0.120-1.el8_10.noarch.rpm1d82a70cabacf5e7619b1160e9835fb5823479c9284a6f9c576b5a583f7218ee-ol8_aarch64_appstream
tomcat-admin-webapps-9.0.120-1.el8_10.noarch.rpmd5aad9ba058c2465991313e536e9e09fc9bfc177daca6e185bfa7933d556296f-ol8_aarch64_appstream
tomcat-docs-webapp-9.0.120-1.el8_10.noarch.rpm67467750e74582d7ec276c9e4e2fdb03b138d56ef6c2e945f3cfac5c612beace-ol8_aarch64_appstream
tomcat-el-3.0-api-9.0.120-1.el8_10.noarch.rpm79a109c6cb07550ce795876ba1c668c1093fa353c2c238e9c2c818dd4f5f01ea-ol8_aarch64_appstream
tomcat-jsp-2.3-api-9.0.120-1.el8_10.noarch.rpmc829b8bc7a10f19dc002a00c8a1cb48a543f8b59747840ea617f8ea23e89b330-ol8_aarch64_appstream
tomcat-lib-9.0.120-1.el8_10.noarch.rpm71f750a476de230294563cd730fbd86db7e1303272499ae3eaf7ad6829aa25a9-ol8_aarch64_appstream
tomcat-servlet-4.0-api-9.0.120-1.el8_10.noarch.rpmac3fe2167ce690727f88bb1e57ea1b84d268ea17c740c5b2559ccf463a7c6ce2-ol8_aarch64_appstream
tomcat-webapps-9.0.120-1.el8_10.noarch.rpmc2b00486612b69c0ab25be8fbb1c3b3af518ba1ca32fc9a3179c7f7eac0e23f3-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) tomcat-9.0.120-1.el8_10.src.rpmd6ec126c6671f79e3692787f805453be6373435bfb28231f9d7e69949aa2e1d7-ol8_x86_64_appstream
tomcat-9.0.120-1.el8_10.noarch.rpm1d82a70cabacf5e7619b1160e9835fb5823479c9284a6f9c576b5a583f7218ee-ol8_x86_64_appstream
tomcat-admin-webapps-9.0.120-1.el8_10.noarch.rpmd5aad9ba058c2465991313e536e9e09fc9bfc177daca6e185bfa7933d556296f-ol8_x86_64_appstream
tomcat-docs-webapp-9.0.120-1.el8_10.noarch.rpm67467750e74582d7ec276c9e4e2fdb03b138d56ef6c2e945f3cfac5c612beace-ol8_x86_64_appstream
tomcat-el-3.0-api-9.0.120-1.el8_10.noarch.rpm79a109c6cb07550ce795876ba1c668c1093fa353c2c238e9c2c818dd4f5f01ea-ol8_x86_64_appstream
tomcat-jsp-2.3-api-9.0.120-1.el8_10.noarch.rpmc829b8bc7a10f19dc002a00c8a1cb48a543f8b59747840ea617f8ea23e89b330-ol8_x86_64_appstream
tomcat-lib-9.0.120-1.el8_10.noarch.rpm71f750a476de230294563cd730fbd86db7e1303272499ae3eaf7ad6829aa25a9-ol8_x86_64_appstream
tomcat-servlet-4.0-api-9.0.120-1.el8_10.noarch.rpmac3fe2167ce690727f88bb1e57ea1b84d268ea17c740c5b2559ccf463a7c6ce2-ol8_x86_64_appstream
tomcat-webapps-9.0.120-1.el8_10.noarch.rpmc2b00486612b69c0ab25be8fbb1c3b3af518ba1ca32fc9a3179c7f7eac0e23f3-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete