Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.5%top 59%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
Medium
Published: Tue May 12 2026 (05/12/2026, 20:44:29 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: tomcat10: * tomcat10-10.1.55-1.hum1 (noarch) * tomcat10-admin-webapps-10.1.55-1.hum1 (noarch) * tomcat10-common-10.1.55-1.hum1 (noarch) * tomcat10-docs-webapp-10.1.55-1.hum1 (noarch) * tomcat10-el-5.0-api-10.1.55-1.hum1 (noarch) * tomcat10-jsp-3.1-api-10.1.55-1.hum1 (noarch) * tomcat10-lib-10.1.55-1.hum1 (noarch) * tomcat10-servlet-6.0-api-10.1.55-1.hum1 (noarch) * tomcat10-user-instance-10.1.55-1.hum1 (noarch) * tomcat10-webapps-10.1.55-1.hum1 (noarch) * tomcat10-10.1.55-1.hum1.src (src)

Affected software

Affected versions
Red HatRed Hat Hardened Imagesnoarchtomcat10-main@noarch

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/17/2026, 10:04:29 UTC

Technical Analysis

This Red Hat security advisory (RHSA-2026:16528) announces a bug fix and enhancement update for Red Hat Hardened Images RPMs, focusing on tomcat10 packages updated to version 10.1.55-1.hum1. The update addresses three CVEs: CVE-2026-42498, CVE-2026-43512, and CVE-2026-43514, which relate to issues categorized under CWE-201 (Information Exposure), CWE-303 (Incorrect Implementation), and CWE-208 (Information Exposure Through Error Message). The advisory does not provide CVSS scores or detailed vulnerability descriptions but classifies the severity as medium. There are no known exploits in the wild. The update is available through Red Hat's standard RPM update channels for hardened images. No cloud service is involved, so remediation is managed by applying the updated RPMs.

Potential Impact

The vulnerabilities addressed involve potential information exposure and implementation errors as indicated by the associated CWEs. The medium severity suggests moderate risk, potentially allowing attackers to gain unintended information or cause incorrect behavior in affected tomcat10 components within Red Hat Hardened Images. No active exploitation has been reported, reducing immediate risk. The impact is limited to environments using the affected RPM packages prior to the update.

Mitigation Recommendations

Red Hat has released updated RPM packages for tomcat10 (version 10.1.55-1.hum1) that fix the identified vulnerabilities. Users of Red Hat Hardened Images should apply these updates promptly to remediate the issues. Since this is not a cloud service, remediation requires manual update of the affected RPMs. No additional mitigation steps are specified or required beyond applying the provided update. Patch status is confirmed by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:16528
Cve Count
3
Additional Cves
["CVE-2026-43512","CVE-2026-43514"]
Cvss Version
null

Threat ID: 6a32705b0b89be68881d44a9

Added to database: 6/17/2026, 10:00:59 AM

Last enriched: 6/17/2026, 10:04:29 AM

Last updated: 6/17/2026, 6:25:22 PM

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses