RHSA-2026:8334HighCVSS 7.5
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (7)
📋 Description
CVE-2025-55668 — org.apache.tomcat/tomcat-catalina: tomcat: Apache Tomcat: session fixation via rewrite valve CVE-2025-55752 — tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possible RCE CVE-2025-55754 — org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation CVE-2025-61795 — tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Denial of service CVE-2025-66614 — tomcat: Client certificate verification bypass due to virtual host mapping CVE-2026-24733 — tomcat: security constraint bypass with HTTP/0.9 CVE-2026-24734 — tomcat: Apache Tomcat: Certificate revocation bypass due to improper OCSP response validation
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:8334
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2025-55668
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2025-61795
- externalhttps://access.redhat.com/security/cve/CVE-2025-55754
- externalhttps://access.redhat.com/security/cve/CVE-2025-55752
- externalhttps://access.redhat.com/security/cve/CVE-2026-24733
- externalhttps://access.redhat.com/security/cve/CVE-2025-66614
- externalhttps://access.redhat.com/security/cve/CVE-2026-24734
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_8334.json