Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 561
Alerts This Week
Warning Icon 1 561

Oracle 10 Tomcat Important Data Encryption Issues and Fixes ELSA-2026-18537

oracle
Calendar Grey July 28, 2026
Scroller Oracle
Oracle Linux 10 updated Tomcat packages address crucial security issues and vulnerabilities. Immediate updates are advised.
Oracle released security updates for Tomcat on Oracle Linux 10 to address various vulnerabilities, including important fixes for information disclosure and encryption issues relate...

Summary

[1:10.1.49-3] - Related: RHEL-168577 Remove unnecessary patch [1:10.1.49-2] - Resolves: RHEL-168577 Remove tomcat clustering JAR from RPM builds Resolves: CVE-2026-29146 tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor Resolves: CVE-2026-34486 tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass [1:10.1.36-3.el10_1.1] - Resolves: RHEL-150719 Certificate revocation bypass due to improper OCSP response validation (CVE-2026-24734)

SRPMs

http://oss.oracle.com/ol10/SRPMS-updates/tomcat-10.1.49-3.el10_2.src.rpm

x86_64

tomcat-10.1.49-3.el10_2.noarch.rpm tomcat-admin-webapps-10.1.49-3.el10_2.noarch.rpm tomcat-docs-webapp-10.1.49-3.el10_2.noarch.rpm tomcat-el-5.0-api-10.1.49-3.el10_2.noarch.rpm tomcat-jsp-3.1-api-10.1.49-3.el10_2.noarch.rpm tomcat-lib-10.1.49-3.el10_2.noarch.rpm tomcat-servlet-6.0-api-10.1.49-3.el10_2.noarch.rpm tomcat-webapps-10.1.49-3.el10_2.noarch.rpm

aarch64

tomcat-10.1.49-3.el10_2.noarch.rpm tomcat-admin-webapps-10.1.49-3.el10_2.noarch.rpm tomcat-docs-webapp-10.1.49-3.el10_2.noarch.rpm tomcat-el-5.0-api-10.1.49-3.el10_2.noarch.rpm tomcat-jsp-3.1-api-10.1.49-3.el10_2.noarch.rpm tomcat-lib-10.1.49-3.el10_2.noarch.rpm tomcat-servlet-6.0-api-10.1.49-3.el10_2.noarch.rpm tomcat-webapps-10.1.49-3.el10_2.noarch.rpm

Severity
important
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2025-46701 CVE-2025-55668 CVE-2025-55754

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.