Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.6%top 55%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
Critical
Published: 06/24/2026 (06/24/2026, 17:15:25 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A security update for Red Hat Hardened Images RPMs addresses multiple vulnerabilities in Apache Tomcat 10, including an improper authentication flaw in the EncryptionInterceptor component used for Tribes cluster communication. This flaw allows a replay attack on encrypted cluster messages if the EncryptionInterceptor is configured, which is not the default setting. The vulnerability requires attacker access to the cluster network and affects only specific Tomcat clustering configurations. Red Hat has released updated RPM packages to fix these issues.

Affected software

Affected versions
>=10.1.0 <10.1.56

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/09/2026, 17:24:52 UTC

Technical Analysis

This advisory covers a critical security update for Red Hat Hardened Images RPMs, specifically Apache Tomcat 10 packages. Among the fixed issues is CVE-2026-55955, an improper authentication vulnerability in the EncryptionInterceptor component used for Tribes cluster communication. This vulnerability enables a remote attacker with access to the cluster network to perform replay attacks on encrypted cluster messages, potentially leading to unauthorized access or data manipulation within the cluster. Exploitation requires the EncryptionInterceptor to be enabled, which is a non-default configuration. Red Hat corrected the severity rating from important to moderate due to the adjacency of the attack vector and complexity required. The update includes tomcat10-10.1.56-1.hum1 and related noarch RPMs. No known exploits are reported in the wild. The advisory references multiple CVEs and CWE identifiers related to authentication bypass and access control issues.

Potential Impact

The impact is limited to Tomcat deployments using the EncryptionInterceptor for Tribes cluster communication. Successful exploitation could allow an attacker to replay encrypted cluster messages, potentially gaining unauthorized access or manipulating cluster data. However, the attack requires network access to the cluster and a non-default configuration, reducing the overall risk. Red Hat rates the impact as moderate with a CVSS 3.1 vector of AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N (4.2). No known active exploitation has been reported.

Mitigation Recommendations

Red Hat has released updated RPM packages (tomcat10-10.1.56-1.hum1 and related components) that fix these vulnerabilities. Users should apply these updates to affected Red Hat Hardened Images. Deployments not using Tomcat clustering or not configuring the EncryptionInterceptor are not affected. It is recommended to restrict cluster communication channels to trusted, isolated networks to mitigate potential replay attacks. No additional mitigations are required beyond applying the official update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:29203
Cve Count
4
Additional Cves
["CVE-2026-53434","CVE-2026-55276","CVE-2026-55955"]
Cvss Version
3.1

Threat ID: 6a44530127e9c79719916caa

Added to database: 06/30/2026, 23:36:33 UTC

Last enriched: 08/09/2026, 17:24:52 UTC

Last updated: 08/13/2026, 04:33:34 UTC

Views: 98

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses