Red Hat Security Advisory: tomcat9 security, bug fix, and enhancement update
🔗 CVE IDs covered (13)
📋 Description
CVE-2025-66614 — tomcat: Client certificate verification bypass due to virtual host mapping CVE-2026-24733 — tomcat: security constraint bypass with HTTP/0.9 CVE-2026-24734 — tomcat: Apache Tomcat: Certificate revocation bypass due to improper OCSP response validation CVE-2026-24880 — Apache Tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension CVE-2026-25854 — Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve CVE-2026-29129 — Apache Tomcat: Apache Tomcat: Configured cipher preference order not preserved CVE-2026-29145 — Apache Tomcat: Apache Tomcat: Authentication bypass due to CLIENT_CERT soft fail misconfiguration CVE-2026-29146 — Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor CVE-2026-32990 — Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix CVE-2026-34483 — Apache Tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve CVE-2026-34486 — Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass CVE-2026-34487 — Apache Tomcat: Apache Tomcat: Information disclosure via sensitive data in log files CVE-2026-34500 — Apache Tomcat: Apache Tomcat: Authentication bypass via client certificate misconfiguration
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:36790
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457020
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457027
- externalhttps://issues.redhat.com/browse/RHEL-185571
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_36790.json