Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-18916

Опубликовано: 29 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-18916: tomcat security update (IMPORTANT)

[1:9.0.117-1]

  • Resolves: RHEL-150714 Certificate revocation bypass due to improper OCSP response validation
  • Resolves: Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled (CVE-2026-34500)
  • Resolves: Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token (CVE-2026-34487)
  • Resolves: Tomcat: The fix for CVE-2026-29146 allowed the bypass of the EncryptInterceptor (CVE-2026-34486)
  • Resolves: Tomcat: Incomplete escaping of JSON access logs (CVE-2026-34483)
  • Resolves: Tomcat: The fix for CVE-2025-66614 was incomplete (CVE-2026-32990)
  • Resolves: Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default (CVE-2026-29146)
  • Resolves: Tomcat: OCSP checks sometimes soft-fail even when soft-fail is disabled (CVE-2026-29145)
  • Resolves: Tomcat: Configured TLS cipher preference order not preserved (CVE-2026-29129)
  • Resolves: Tomcat: Occasionally open redirect (CVE-2026-25854)
  • Resolves: Tomcat: Request smuggling via invalid chunk extension (CVE-2026-24880)
  • Resolves: Tomcat: Incomplete OCSP verification checks (CVE-2026-24734)
  • Resolves: Tomcat: Security constraint bypass (CVE-2026-24733)
  • Resolves: Tomcat: Client certificate verification bypass due to virtual host mapping (CVE-2025-66614)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

tomcat

9.0.117-1.el9_8

tomcat-admin-webapps

9.0.117-1.el9_8

tomcat-docs-webapp

9.0.117-1.el9_8

tomcat-el-3.0-api

9.0.117-1.el9_8

tomcat-jsp-2.3-api

9.0.117-1.el9_8

tomcat-lib

9.0.117-1.el9_8

tomcat-servlet-4.0-api

9.0.117-1.el9_8

tomcat-webapps

9.0.117-1.el9_8

Oracle Linux x86_64

tomcat

9.0.117-1.el9_8

tomcat-admin-webapps

9.0.117-1.el9_8

tomcat-docs-webapp

9.0.117-1.el9_8

tomcat-el-3.0-api

9.0.117-1.el9_8

tomcat-jsp-2.3-api

9.0.117-1.el9_8

tomcat-lib

9.0.117-1.el9_8

tomcat-servlet-4.0-api

9.0.117-1.el9_8

tomcat-webapps

9.0.117-1.el9_8

Связанные уязвимости

rocky
2 месяца назад

Important: tomcat security update

oracle-oval
10 дней назад

ELSA-2026-18537: tomcat security update (IMPORTANT)

oracle-oval
10 дней назад

ELSA-2026-18536: tomcat9 security update (IMPORTANT)

CVSS3: 7.3
ubuntu
около 1 года назад

Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue.

CVSS3: 6.5
redhat
около 1 года назад

Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue.