Описание
Important: tomcat security, bug fix, and enhancement update
Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.
Security Fix(es):
-
Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor (CVE-2026-29146)
-
Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass (CVE-2026-34486)
Bug Fix(es) and Enhancement(s):
- Remove tomcat clustering JAR from RPM builds (JIRA:Rocky Linux-183993)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Затронутые продукты
Rocky Linux 8
Связанные CVE
Исправления
- Red Hat - 2457020
- Red Hat - 2457027
Связанные уязвимости
ELSA-2026-37137: tomcat security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-36879: tomcat security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-36790: tomcat9 security, bug fix, and enhancement update (IMPORTANT)