rlsa-2026:68660

CVSS 7.3 osv_rocky
Description

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990) * tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512) * tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293) * tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. (CVE-2026-42498) * tomcat-coyote: tomcat: Improper Authorization allows security bypass (CVE-2026-43515) * tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) * tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) * tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084) Bug Fix(es) and Enhancement(s): * Tomcat fails to respond to client connections when using Java 8 [rhel-9.8] (JIRA:Rocky Linux-257456) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "source": "https://storage.googleapis.com/resf-osv-data/RLSA-2026:68660.json"
      },
      "package": {
        "ecosystem": "Rocky Linux:9",
        "name": "tomcat",
        "purl": "pkg:rpm/rocky-linux/tomcat?distro=rocky-linux-9-x86-64&epoch=1"
      },
      "ranges": [
        {
          "database_specific": {
            "yum_repository": "AppStream"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1:9.0.120-2.el9_8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "credits": [
    {
      "name": "Rocky Enterprise Software Foundation"
    },
    {
      "name": "Red Hat"
    }
  ],
  "database_specific": {
    "license": "CC-BY-4.0",
    "license_url": "https://creativecommons.org/licenses/by/4.0/",
    "source_advisory": "RHSA-2026:68660"
  },
  "details": "Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.\n\nSecurity Fix(es):\n\n* Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990)\n\n* tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512)\n\n* tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293)\n\n* tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. (CVE-2026-42498)\n\n* tomcat-coyote: tomcat: Improper Authorization allows security bypass (CVE-2026-43515)\n\n* tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513)\n\n* tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083)\n\n* tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084)\n\nBug Fix(es) and Enhancement(s):\n\n* Tomcat fails to respond to client connections when using Java 8 [rhel-9.8] (JIRA:Rocky Linux-257456)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.",
  "id": "RLSA-2026:68660",
  "modified": "2026-09-19T12:30:02.573355431Z",
  "published": "2026-09-19T12:04:58.550496Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://errata.rockylinux.org/RLSA-2026:68660"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457025"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476511"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476513"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476516"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476519"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476520"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499917"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499931"
    },
    {
      "type": "ADVISORY",
      "url": "https://access.redhat.com/errata/RHSA-2026:68660"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Moderate: tomcat security, bug fix, and enhancement update",
  "upstream": [
    "CVE-2026-32990",
    "CVE-2026-41293",
    "CVE-2026-42498",
    "CVE-2026-43512",
    "CVE-2026-43513",
    "CVE-2026-43515",
    "CVE-2026-59083",
    "CVE-2026-59084"
  ]
}
View JSON API Download JSON