[El-errata] ELSA-2026-69259 Moderate: Oracle Linux 10 tomcat update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Sep 22 09:12:18 UTC 2026


Oracle Linux Security Advisory ELSA-2026-69259

http://linux.oracle.com/errata/ELSA-2026-69259.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
tomcat-10.1.49-4.el10_2.noarch.rpm
tomcat-admin-webapps-10.1.49-4.el10_2.noarch.rpm
tomcat-docs-webapp-10.1.49-4.el10_2.noarch.rpm
tomcat-el-5.0-api-10.1.49-4.el10_2.noarch.rpm
tomcat-jsp-3.1-api-10.1.49-4.el10_2.noarch.rpm
tomcat-lib-10.1.49-4.el10_2.noarch.rpm
tomcat-servlet-6.0-api-10.1.49-4.el10_2.noarch.rpm
tomcat-webapps-10.1.49-4.el10_2.noarch.rpm

aarch64:
tomcat-10.1.49-4.el10_2.noarch.rpm
tomcat-admin-webapps-10.1.49-4.el10_2.noarch.rpm
tomcat-docs-webapp-10.1.49-4.el10_2.noarch.rpm
tomcat-el-5.0-api-10.1.49-4.el10_2.noarch.rpm
tomcat-jsp-3.1-api-10.1.49-4.el10_2.noarch.rpm
tomcat-lib-10.1.49-4.el10_2.noarch.rpm
tomcat-servlet-6.0-api-10.1.49-4.el10_2.noarch.rpm
tomcat-webapps-10.1.49-4.el10_2.noarch.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/tomcat-10.1.49-4.el10_2.src.rpm

Related CVEs:

CVE-2026-32990
CVE-2026-41293
CVE-2026-42498
CVE-2026-43512
CVE-2026-43513
CVE-2026-43515




Description of changes:

[1:10.1.49-4]
- Resolves: RHEL-192817 tomcat: HTTP/2 request headers not validated (CVE-2026-41293)
- Resolves: RHEL-192648 tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990)
- Resolves: RHEL-238208 tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498)
- Resolves: RHEL-238224 tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513)
- Resolves: RHEL-238259 tomcat: Improper Authorization allows security bypass (CVE-2026-43515)
- Resolves: RHEL-238284 tomcat: Authentication bypass via digest authentication (CVE-2026-43512)




More information about the El-errata mailing list