Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 6.3%top 7.2%

Red Hat Security Advisory: Red Hat JBoss Web Server 7.0.0 security release

0
High
Published: 07/14/2026 (07/14/2026, 18:04:24 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat JBoss Web Server 7.0.0 includes multiple security fixes addressing vulnerabilities in Apache Tomcat components such as EncryptInterceptor bypass, padding oracle information disclosure, improper authorization, denial of service, HTTP/2 header validation, authentication bypass, and security constraint bypass. These vulnerabilities affect the confidentiality and authorization mechanisms of the server. The release replaces version 6.2.3 and is available for RHEL 8, 9, and 10.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected software

Affected versions
>=7.0.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 01:00:09 UTC

Technical Analysis

Red Hat JBoss Web Server 7.0.0 is a fully integrated Java web application hosting platform including Apache Tomcat and related components. This release addresses several security vulnerabilities including CVE-2026-29146 (padding oracle information disclosure in EncryptInterceptor), CVE-2026-34486 (missing encryption due to EncryptInterceptor bypass), CVE-2026-43515 (improper authorization allowing security bypass), CVE-2026-41284 (denial of service via uncontrolled resource allocation), CVE-2026-41293 (HTTP/2 request headers not validated), CVE-2026-42498 (information disclosure via HTTP Authentication header exposure during WebSocket authentication), CVE-2026-43512 (authentication bypass via digest authentication), CVE-2026-43513 (improper handling of case sensitivity in LockOutRealm), CVE-2026-43514 (information disclosure via AJP secret timing discrepancy), and CVE-2026-55956 (improper authorization allowing security constraint bypass). These issues impact confidentiality and authorization controls. The update replaces Red Hat JBoss Web Server 6.2.3 and is available for RHEL 8, 9, and 10 platforms.

Potential Impact

The vulnerabilities collectively allow attackers to bypass encryption, disclose sensitive information, bypass authentication and authorization controls, and cause denial of service conditions. This can lead to unauthorized access to sensitive data and security constraints, potentially compromising the confidentiality and integrity of hosted Java web applications.

Mitigation Recommendations

Red Hat has released Red Hat JBoss Web Server 7.0.0 as a security update that addresses these vulnerabilities. Users should upgrade to this version to remediate the issues. Before applying this update, ensure all previously released errata relevant to your system have been applied. Follow the official Red Hat guidance for applying the update: https://access.redhat.com/articles/11258. No additional mitigation steps are indicated beyond applying the official update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:36787
Cve Count
2
Additional Cves
["CVE-2026-34486"]
Cvss Version
3.1

Threat ID: 6a4f6c1068715ace43153770

Added to database: 07/09/2026, 09:38:24 UTC

Last enriched: 07/31/2026, 01:00:09 UTC

Last updated: 07/31/2026, 19:24:46 UTC

Views: 59

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses