Skip to main content
EPSS 4.1%top 9.6%

Security update for tomcat11

0
Medium
Published: 07/13/2026 (07/13/2026, 16:24:32 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for tomcat11 fixes the following issues Update to Tomcat 11.0.23. Security issues fixed: - CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). - CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). - CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). - CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). - CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). - CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: - Upgrade libtcnative to v2 (bsc#1232390) - Tomcat 11.0.23: * Catalina + Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) + Fix: Lower the log level to debug when OpenSSL initialization fails in OpenSSLLifecycleListener to avoid stack traces when libssl.so is not present and to align the behavior of the isAvailable() check with the AprLifecycleListener and gracefully fail when natives are not present. (csutherl) + Fix: 70038: Cookie.clone() should also clone the internal attribute map. (markt) + Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) + Fix: Cleaner handling of invalid SPNEGO tokens. (remm) + Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) + Fix: Incorrect session average life calculation. (remm) + Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) + Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) + Fix: Fix container event cleanups in some edge cases. (remm) + Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) + Fix: Fix hour unit used by ExpiresFilter. (remm) + Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) + Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) + Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) + Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) + Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) + Fix: Fix shared lock expiration in WebDAV. (remm) + Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) + Fix: Skip BOM when serving files with UTF-32 encoding. (remm) + Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) + Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) + Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) + Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) + Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) + Fix: Fix connection leak in ProxyErrorReportValve. (remm) + Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) + Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) + Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) + Fix: Fix SSO cookie partitioned configuration. (remm) + Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) + Fix: 70048: Correctly handle asynchronous requ

Affected software

Affected versions
=11.0.23-0.1.hum1Red HatRed Hat Hardened Imagesnoarchtomcat11-main@noarchSUSEtomcat11-11.0.23-160000.1.1.noarchtomcat11-admin-webapps-11.0.23-160000.1.1.noarchtomcat11-doc-11.0.23-160000.1.1.noarch

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:58:41 UTC

Technical Analysis

The advisory covers a set of vulnerabilities affecting Red Hat Hardened Images RPMs, including Apache Tomcat 11.0.23-0.1.hum1 packages. One detailed vulnerability (CVE-2026-55955) involves an improper authentication flaw in the EncryptionInterceptor component used for Tribes cluster communication in Apache Tomcat. This flaw allows a remote attacker with access to the cluster network to perform replay attacks against encrypted cluster messages. Exploitation requires the EncryptionInterceptor to be enabled, which is not the default configuration. Red Hat rates this vulnerability as moderate severity with a CVSS 3.1 vector of AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N (score 4.2). The advisory lists multiple CVEs but does not provide explicit patch availability details. The update includes new RPM versions of tomcat11 packages as bug fixes and enhancements.

Potential Impact

The primary impact is unauthorized access or manipulation of data within the Tomcat cluster component via replay attacks on encrypted cluster messages. This affects only deployments using the EncryptionInterceptor for Tribes cluster communication, which is a non-default configuration. The vulnerability does not affect default Tomcat deployments without clustering or without the EncryptionInterceptor enabled. Red Hat downgraded the severity from important to moderate due to the requirement of adjacent network access and high attack complexity. Other listed CVEs in the advisory may have additional impacts but are not detailed here.

Mitigation Recommendations

Red Hat advises that only Tomcat deployments configured with the EncryptionInterceptor for Tribes cluster communication are affected. Mitigation includes ensuring cluster communication channels are restricted to trusted, isolated networks. The advisory does not explicitly confirm that a patch is available for these vulnerabilities; it provides updated RPMs as bug fixes and enhancements. Users should monitor Red Hat's official errata and update to the latest RPM versions when available. If not using the EncryptionInterceptor or clustering, no action is required for this specific vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:32960
Cve Count
5
Additional Cves
["CVE-2026-53404","CVE-2026-53434","CVE-2026-55276","CVE-2026-55955"]
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a44530127e9c79719916bc3

Added to database: 06/30/2026, 23:36:33 UTC

Last enriched: 08/16/2026, 17:58:41 UTC

Last updated: 09/29/2026, 18:11:19 UTC

Views: 200

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses