Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
A security update for Red Hat Hardened Images RPMs addresses multiple vulnerabilities in Apache Tomcat 10, including an improper authentication flaw in the EncryptionInterceptor component used for Tribes cluster communication. This flaw allows a replay attack on encrypted cluster messages if the EncryptionInterceptor is configured, which is not the default setting. The vulnerability requires attacker access to the cluster network and affects only specific Tomcat clustering configurations. Red Hat has released updated RPM packages to fix these issues.
AI Analysis
Technical Summary
This advisory covers a critical security update for Red Hat Hardened Images RPMs, specifically Apache Tomcat 10 packages. Among the fixed issues is CVE-2026-55955, an improper authentication vulnerability in the EncryptionInterceptor component used for Tribes cluster communication. This vulnerability enables a remote attacker with access to the cluster network to perform replay attacks on encrypted cluster messages, potentially leading to unauthorized access or data manipulation within the cluster. Exploitation requires the EncryptionInterceptor to be enabled, which is a non-default configuration. Red Hat corrected the severity rating from important to moderate due to the adjacency of the attack vector and complexity required. The update includes tomcat10-10.1.56-1.hum1 and related noarch RPMs. No known exploits are reported in the wild. The advisory references multiple CVEs and CWE identifiers related to authentication bypass and access control issues.
Potential Impact
The impact is limited to Tomcat deployments using the EncryptionInterceptor for Tribes cluster communication. Successful exploitation could allow an attacker to replay encrypted cluster messages, potentially gaining unauthorized access or manipulating cluster data. However, the attack requires network access to the cluster and a non-default configuration, reducing the overall risk. Red Hat rates the impact as moderate with a CVSS 3.1 vector of AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N (4.2). No known active exploitation has been reported.
Mitigation Recommendations
Red Hat has released updated RPM packages (tomcat10-10.1.56-1.hum1 and related components) that fix these vulnerabilities. Users should apply these updates to affected Red Hat Hardened Images. Deployments not using Tomcat clustering or not configuring the EncryptionInterceptor are not affected. It is recommended to restrict cluster communication channels to trusted, isolated networks to mitigate potential replay attacks. No additional mitigations are required beyond applying the official update.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
A security update for Red Hat Hardened Images RPMs addresses multiple vulnerabilities in Apache Tomcat 10, including an improper authentication flaw in the EncryptionInterceptor component used for Tribes cluster communication. This flaw allows a replay attack on encrypted cluster messages if the EncryptionInterceptor is configured, which is not the default setting. The vulnerability requires attacker access to the cluster network and affects only specific Tomcat clustering configurations. Red Hat has released updated RPM packages to fix these issues.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers a critical security update for Red Hat Hardened Images RPMs, specifically Apache Tomcat 10 packages. Among the fixed issues is CVE-2026-55955, an improper authentication vulnerability in the EncryptionInterceptor component used for Tribes cluster communication. This vulnerability enables a remote attacker with access to the cluster network to perform replay attacks on encrypted cluster messages, potentially leading to unauthorized access or data manipulation within the cluster. Exploitation requires the EncryptionInterceptor to be enabled, which is a non-default configuration. Red Hat corrected the severity rating from important to moderate due to the adjacency of the attack vector and complexity required. The update includes tomcat10-10.1.56-1.hum1 and related noarch RPMs. No known exploits are reported in the wild. The advisory references multiple CVEs and CWE identifiers related to authentication bypass and access control issues.
Potential Impact
The impact is limited to Tomcat deployments using the EncryptionInterceptor for Tribes cluster communication. Successful exploitation could allow an attacker to replay encrypted cluster messages, potentially gaining unauthorized access or manipulating cluster data. However, the attack requires network access to the cluster and a non-default configuration, reducing the overall risk. Red Hat rates the impact as moderate with a CVSS 3.1 vector of AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N (4.2). No known active exploitation has been reported.
Mitigation Recommendations
Red Hat has released updated RPM packages (tomcat10-10.1.56-1.hum1 and related components) that fix these vulnerabilities. Users should apply these updates to affected Red Hat Hardened Images. Deployments not using Tomcat clustering or not configuring the EncryptionInterceptor are not affected. It is recommended to restrict cluster communication channels to trusted, isolated networks to mitigate potential replay attacks. No additional mitigations are required beyond applying the official update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:29203
- Cve Count
- 4
- Additional Cves
- ["CVE-2026-53434","CVE-2026-55276","CVE-2026-55955"]
- Cvss Version
- 3.1
Threat ID: 6a44530127e9c79719916caa
Added to database: 06/30/2026, 23:36:33 UTC
Last enriched: 08/09/2026, 17:24:52 UTC
Last updated: 08/13/2026, 04:33:34 UTC
Views: 98
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.