[El-errata] ELSA-2026-68660 Moderate: Oracle Linux 9 tomcat security, bug fix, and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Mon Sep 21 13:24:16 UTC 2026


Oracle Linux Security Advisory ELSA-2026-68660

http://linux.oracle.com/errata/ELSA-2026-68660.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
tomcat-9.0.120-2.el9_8.noarch.rpm
tomcat-admin-webapps-9.0.120-2.el9_8.noarch.rpm
tomcat-docs-webapp-9.0.120-2.el9_8.noarch.rpm
tomcat-el-3.0-api-9.0.120-2.el9_8.noarch.rpm
tomcat-jsp-2.3-api-9.0.120-2.el9_8.noarch.rpm
tomcat-lib-9.0.120-2.el9_8.noarch.rpm
tomcat-servlet-4.0-api-9.0.120-2.el9_8.noarch.rpm
tomcat-webapps-9.0.120-2.el9_8.noarch.rpm

aarch64:
tomcat-9.0.120-2.el9_8.noarch.rpm
tomcat-admin-webapps-9.0.120-2.el9_8.noarch.rpm
tomcat-docs-webapp-9.0.120-2.el9_8.noarch.rpm
tomcat-el-3.0-api-9.0.120-2.el9_8.noarch.rpm
tomcat-jsp-2.3-api-9.0.120-2.el9_8.noarch.rpm
tomcat-lib-9.0.120-2.el9_8.noarch.rpm
tomcat-servlet-4.0-api-9.0.120-2.el9_8.noarch.rpm
tomcat-webapps-9.0.120-2.el9_8.noarch.rpm


SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/tomcat-9.0.120-2.el9_8.src.rpm

Related CVEs:

CVE-2026-32990
CVE-2026-41293
CVE-2026-42498
CVE-2026-43512
CVE-2026-43513
CVE-2026-43515
CVE-2026-59083
CVE-2026-59084




Description of changes:

[1:9.0.120-1]
- Resolves: RHEL-192825 HTTP/2 request headers not validated (CVE-2026-41293)
- Resolves: RHEL-192659 Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990)
- Resolves: RHEL-219565 Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083)
- Resolves: RHEL-219573 Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084)
- Resolves: RHEL-238189 tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498)
- Resolves: RHEL-238247 tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513)
- Resolves: RHEL-238277 tomcat: Improper Authorization allows security bypass (CVE-2026-43515)
- Resolves: RHEL-238302 tomcat: Authentication bypass via digest authentication (CVE-2026-43512)
- Related: RHEL-183992 Remove tomcat clustering JAR from RPM builds

[1:9.0.110-1]
- Resolves: RHEL-148687
  Update to 9.0.110 and compile with Java 25 to enable FFM features for PQC support

[1:9.0.87-7]
- Resolves: RHEL-124516
  tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752)
- Resolves: RHEL-132561
  tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651)

[1:9.0.87-6]
- Resolves: RHEL-102201
  tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames (CVE-2025-48989)

[1:9.0.87-5]
- Resolves: RHEL-108489
  tomcat: Apache Commons FileUpload DOS via part headers (CVE-2025-48976)
- Resolves: RHEL-108497
  tomcat: Dos in multipart upload (CVE-2025-48988)
- Resolves: RHEL-108505
  tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)
- Resolves: RHEL-108513
  tomcat: Denial of service (CVE-2025-52434)
- Resolves: RHEL-108529
  tomcat: Denial of service (CVE-2025-52520)
- Resolves: RHEL-108523
  tomcat: Denial of service (CVE-2025-53506)

[1:9.0.87-4]
- Resolves: RHEL-91763
  tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)
- Resolves: RHEL-71985
  tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)

[1:9.0.87-3]
- Resolves: RHEL-82945
  tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT (CVE-2025-24813)
- Resolves: RHEL-71723
  tomcat: RCE due to TOCTOU issue in JSP compilation (CVE-2024-50379)

[1:9.0.87-2]
- Resolves: RHEL-46163
  tomcat: Improper Handling of Exceptional Conditions (CVE-2024-34750)
- Resolves: RHEL-18245 - OpenJDK 21 support for RHEL Tomcat




More information about the El-errata mailing list