ELSA-2026-69259

ELSA-2026-69259 - tomcat update

Type:SECURITY
Impact:MODERATE
Release Date:2026-09-21

Description


[1:10.1.49-4]
- Resolves: RHEL-192817 tomcat: HTTP/2 request headers not validated (CVE-2026-41293)
- Resolves: RHEL-192648 tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990)
- Resolves: RHEL-238208 tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498)
- Resolves: RHEL-238224 tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513)
- Resolves: RHEL-238259 tomcat: Improper Authorization allows security bypass (CVE-2026-43515)
- Resolves: RHEL-238284 tomcat: Authentication bypass via digest authentication (CVE-2026-43512)


Related CVEs


CVE-2026-32990
CVE-2026-41293
CVE-2026-42498
CVE-2026-43512
CVE-2026-43513
CVE-2026-43515

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) tomcat-10.1.49-4.el10_2.src.rpme1379da0bdbee301ef22536023d5302c7f94c79953921fff54d1bdcaabe1b6d5-ol10_aarch64_appstream
tomcat-10.1.49-4.el10_2.noarch.rpmc993d9d8067fd71d7653488dab549ebb84bf4cf0e406cdfaaeb0764a9e3cd8d6-ol10_aarch64_appstream
tomcat-admin-webapps-10.1.49-4.el10_2.noarch.rpm0967fe92710b6b1444fa97b3aa6a3f0fbdc2b129b343e505471cd9a2e8d9b8da-ol10_aarch64_appstream
tomcat-docs-webapp-10.1.49-4.el10_2.noarch.rpmad765ca281fbed0e56bfc08ef3d5921d66eff2782f4e8ba843237bc664ce72b6-ol10_aarch64_appstream
tomcat-el-5.0-api-10.1.49-4.el10_2.noarch.rpmbfab28842b9f1fa62b6cfb7966f6e95a9f28bc5018acc5fbc4823f180596e5a6-ol10_aarch64_appstream
tomcat-jsp-3.1-api-10.1.49-4.el10_2.noarch.rpm1b6e1203318f8cbe219b75f5f2f37d420889ca02f97ebab7dbe46dd61cdcb608-ol10_aarch64_appstream
tomcat-lib-10.1.49-4.el10_2.noarch.rpmac1f3afa19fe8d2b4484385e30f32c8c911f56642713bff9578714a07f23fae7-ol10_aarch64_appstream
tomcat-servlet-6.0-api-10.1.49-4.el10_2.noarch.rpm3b26402020c7db3985f022650f4c219dc115da32a854944698d7a9c83efc53cf-ol10_aarch64_appstream
tomcat-webapps-10.1.49-4.el10_2.noarch.rpm20d170d2172160e461b237e2c3ce9b829fc16aca5a1de0a2e7009ffa42aaf96e-ol10_aarch64_appstream
Oracle Linux 10 (x86_64) tomcat-10.1.49-4.el10_2.src.rpme1379da0bdbee301ef22536023d5302c7f94c79953921fff54d1bdcaabe1b6d5-ol10_x86_64_appstream
tomcat-10.1.49-4.el10_2.noarch.rpmc993d9d8067fd71d7653488dab549ebb84bf4cf0e406cdfaaeb0764a9e3cd8d6-ol10_x86_64_appstream
tomcat-admin-webapps-10.1.49-4.el10_2.noarch.rpm0967fe92710b6b1444fa97b3aa6a3f0fbdc2b129b343e505471cd9a2e8d9b8da-ol10_x86_64_appstream
tomcat-docs-webapp-10.1.49-4.el10_2.noarch.rpmad765ca281fbed0e56bfc08ef3d5921d66eff2782f4e8ba843237bc664ce72b6-ol10_x86_64_appstream
tomcat-el-5.0-api-10.1.49-4.el10_2.noarch.rpmbfab28842b9f1fa62b6cfb7966f6e95a9f28bc5018acc5fbc4823f180596e5a6-ol10_x86_64_appstream
tomcat-jsp-3.1-api-10.1.49-4.el10_2.noarch.rpm1b6e1203318f8cbe219b75f5f2f37d420889ca02f97ebab7dbe46dd61cdcb608-ol10_x86_64_appstream
tomcat-lib-10.1.49-4.el10_2.noarch.rpmac1f3afa19fe8d2b4484385e30f32c8c911f56642713bff9578714a07f23fae7-ol10_x86_64_appstream
tomcat-servlet-6.0-api-10.1.49-4.el10_2.noarch.rpm3b26402020c7db3985f022650f4c219dc115da32a854944698d7a9c83efc53cf-ol10_x86_64_appstream
tomcat-webapps-10.1.49-4.el10_2.noarch.rpm20d170d2172160e461b237e2c3ce9b829fc16aca5a1de0a2e7009ffa42aaf96e-ol10_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete