Skip to main content
EPSS 0.6%top 51%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
Medium
Published: 05/12/2026 (05/12/2026, 20:44:29 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: tomcat10: * tomcat10-10.1.55-1.hum1 (noarch) * tomcat10-admin-webapps-10.1.55-1.hum1 (noarch) * tomcat10-common-10.1.55-1.hum1 (noarch) * tomcat10-docs-webapp-10.1.55-1.hum1 (noarch) * tomcat10-el-5.0-api-10.1.55-1.hum1 (noarch) * tomcat10-jsp-3.1-api-10.1.55-1.hum1 (noarch) * tomcat10-lib-10.1.55-1.hum1 (noarch) * tomcat10-servlet-6.0-api-10.1.55-1.hum1 (noarch) * tomcat10-user-instance-10.1.55-1.hum1 (noarch) * tomcat10-webapps-10.1.55-1.hum1 (noarch) * tomcat10-10.1.55-1.hum1.src (src)

Affected software

Affected versions
Red HatRed Hat Hardened Imagesnoarchtomcat10-main@noarch

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 18:57:23 UTC

Technical Analysis

The Red Hat security advisory RHSA-2026:16528 updates multiple Apache Tomcat 10 RPM packages in Red Hat Hardened Images to address several vulnerabilities including CVE-2026-43512. This CVE describes an authentication bypass vulnerability in Apache Tomcat's DIGEST authentication mechanism, where any unknown user can authenticate by submitting the password 'null'. Although this allows bypassing authentication controls, the unknown user does not gain roles or impersonate existing users, limiting the impact. Red Hat notes that DIGEST authentication is not commonly enabled by default in production environments. The advisory recommends disabling DIGEST authentication if it is not essential. The update includes new RPM versions of tomcat10 packages but does not explicitly confirm a patch status. No active exploitation is known.

Potential Impact

The authentication bypass vulnerability (CVE-2026-43512) allows remote attackers to authenticate as unknown users if DIGEST authentication is enabled, potentially gaining unauthorized access to applications protected by this method. However, since the unknown user is not mapped to any valid roles, the actual access gained is limited by application authorization constraints. There is no credential theft or impersonation of existing users. The impact is medium severity due to the limited access and the uncommon use of DIGEST authentication in production.

Mitigation Recommendations

Red Hat recommends disabling DIGEST authentication in Apache Tomcat if it is not essential to your environment. This involves modifying the server's authentication configuration to use alternative methods and restarting the service. The advisory includes updated RPM packages for tomcat10, which should be applied to incorporate the fixes and enhancements. Patch status is not explicitly confirmed; check the vendor advisory for the latest remediation guidance. No urgent action is required if DIGEST authentication is not used.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:16528
Cve Count
3
Additional Cves
["CVE-2026-43512","CVE-2026-43514"]
State
PUBLISHED

Threat ID: 6a32705b0b89be68881d44a9

Added to database: 06/17/2026, 10:00:59 UTC

Last enriched: 08/10/2026, 18:57:23 UTC

Last updated: 09/15/2026, 22:01:34 UTC

Views: 57

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses