Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 561
Alerts This Week
Warning Icon 1 561

Oracle Tomcat Important Security Fixes Advisory ELSA-2026-25341

oracle
Calendar Grey July 28, 2026
Scroller Oracle
Oracle Linux 10 update addresses several Tomcat issues including certificate bypass vulnerabilities and more.
Oracle Linux has released security updates for Tomcat 9 addressing multiple vulnerabilities, including certificate validation issues and potential security bypasses, across various...

Summary

[1:9.0.117-2] - Resolves: RHEL-185571 Remove tomcat clustering JAR from RPM builds [1:9.0.117-1] - Resolves: RHEL-150720 Tomcat: Certificate revocation bypass due to improper OCSP response validation (CVE-2026-24734) - Resolves: Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled (CVE-2026-34500) - Resolves: Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token (CVE-2026-34487) - Resolves: Tomcat: The fix for CVE-2026-29146 allowed the bypass of the EncryptInterceptor (CVE-2026-34486) - Resolves: Tomcat: Incomplete escaping of JSON access logs (CVE-2026-34483) - Resolves: Tomcat: The fix for CVE-2025-66614 was incomplete (CVE-2026-32990) - Resolves: Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default (CVE-2026-29146) - Resolves: Tomcat: OCSP checks sometimes soft-fail even when soft-fail is disabled (CVE-2026-29145) - Resolves: Tomcat: Configured TLS cipher preference order not pre...

Read the Full Advisory

SRPMs

http://oss.oracle.com/ol10/SRPMS-updates/tomcat9-9.0.117-2.el10_2.src.rpm

x86_64

tomcat9-9.0.117-2.el10_2.noarch.rpm tomcat9-admin-webapps-9.0.117-2.el10_2.noarch.rpm tomcat9-docs-webapp-9.0.117-2.el10_2.noarch.rpm tomcat9-el-3.0-api-9.0.117-2.el10_2.noarch.rpm tomcat9-jsp-2.3-api-9.0.117-2.el10_2.noarch.rpm tomcat9-lib-9.0.117-2.el10_2.noarch.rpm tomcat9-servlet-4.0-api-9.0.117-2.el10_2.noarch.rpm tomcat9-webapps-9.0.117-2.el10_2.noarch.rpm

aarch64

tomcat9-9.0.117-2.el10_2.noarch.rpm tomcat9-admin-webapps-9.0.117-2.el10_2.noarch.rpm tomcat9-docs-webapp-9.0.117-2.el10_2.noarch.rpm tomcat9-el-3.0-api-9.0.117-2.el10_2.noarch.rpm tomcat9-jsp-2.3-api-9.0.117-2.el10_2.noarch.rpm tomcat9-lib-9.0.117-2.el10_2.noarch.rpm tomcat9-servlet-4.0-api-9.0.117-2.el10_2.noarch.rpm tomcat9-webapps-9.0.117-2.el10_2.noarch.rpm

Severity
important
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2026-24734

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.