tomcat-9.0.120-2.el9_8

エラータID: AXSA:2026-1883:07

リリース日: 
2026/09/21 Monday - 23:41
題名: 
tomcat-9.0.120-2.el9_8
影響のあるチャネル: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.

Security Fix(es):

* Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990)
* tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512)
* tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293)
* tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. (CVE-2026-42498)
* tomcat-coyote: tomcat: Improper Authorization allows security bypass (CVE-2026-43515)
* tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513)
* tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083)
* tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084)

Bug Fix(es) and Enhancement(s):

* Tomcat fails to respond to client connections when using Java 8 [rhel-9.8] (JIRA:RHEL-257456)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-32990
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
CVE-2026-41293
Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
CVE-2026-42498
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
CVE-2026-43512
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
CVE-2026-43513
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
CVE-2026-43515
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
CVE-2026-59083
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
CVE-2026-59084
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. tomcat-9.0.120-2.el9_8.src.rpm
    MD5: a92b24ad71e7b046c4c5931b65dedca5
    SHA-256: b52a410aa6437a42f4ae4e299d202295f105bcd03183dc18453b537541a3a00c
    Size: 7.40 MB

Asianux Server 9 for x86_64
  1. tomcat-9.0.120-2.el9_8.noarch.rpm
    MD5: 8890d31f427d396102a3246a88030c36
    SHA-256: e021979c9b7cb2d1fc3b2eb21744369022871e64f3d2d76960f78488a3d11ee9
    Size: 99.50 kB
  2. tomcat-admin-webapps-9.0.120-2.el9_8.noarch.rpm
    MD5: 40386323f4edcb2e819ccb701327d57f
    SHA-256: 878e1aa08b64fed1be1ccb2821715f283cec6d62a3f45070dc7ef730abd1e55b
    Size: 84.34 kB
  3. tomcat-docs-webapp-9.0.120-2.el9_8.noarch.rpm
    MD5: 3ae4f974872a21833b53572a47494240
    SHA-256: d266a0b2e77eddcf67f5bbda71108afa9403fa3814b6304ea1c91a1838529ce6
    Size: 1.52 MB
  4. tomcat-el-3.0-api-9.0.120-2.el9_8.noarch.rpm
    MD5: 180d318061f37ac81f40621f7399c7a2
    SHA-256: c98c2694fc87ee4a7828a421ec4e585a236656fce29b78e9f541332d9d107074
    Size: 105.18 kB
  5. tomcat-jsp-2.3-api-9.0.120-2.el9_8.noarch.rpm
    MD5: c9297e51cd3b54b27edea0c0c3f8b22f
    SHA-256: 44bed233c862d3672bd3a96f2d8139c6ddc4ea2ff0951bfd28dd7b5bf64c6a74
    Size: 73.17 kB
  6. tomcat-lib-9.0.120-2.el9_8.noarch.rpm
    MD5: b49761db6340ad8dcb450c6aa01311c2
    SHA-256: d60876dc7b15612fc9da604bf3774dd90644f8cb26dccffa858c798190e77e2c
    Size: 6.08 MB
  7. tomcat-servlet-4.0-api-9.0.120-2.el9_8.noarch.rpm
    MD5: 7581925c953b2b330827a2bf02c6bc44
    SHA-256: 63288244a5628fdd65d975087ede39e7ddcada1f2a0dc995911011f58cd01e55
    Size: 284.69 kB
  8. tomcat-webapps-9.0.120-2.el9_8.noarch.rpm
    MD5: 4f8e7e85c6fa7af7c4e0a4ea17be6e88
    SHA-256: 3f9689cede037c2e9d19e3a6cba898fddbaf5ce03aa2d37b41203def91463b05
    Size: 76.10 kB