Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.8%top 48%

Red Hat Security Advisory: Red Hat JBoss Web Server 6.2.4 release and security update

0
High
Published: 07/22/2026 (07/22/2026, 12:26:18 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat JBoss Web Server 6.2.4 includes multiple security fixes addressing vulnerabilities in Apache Tomcat components such as tomcat-coyote and tomcat-catalina. These fixes resolve issues including HTTP/2 header validation, information disclosure via AJP secret timing, authentication bypasses, improper authorization, denial of service due to uncontrolled resource allocation, and security constraint bypasses. The update replaces version 6.2.3 and is available for Red Hat Enterprise Linux 8, 9, and 10.

Affected software

suse/tomcat
pkg:rpm/suse/tomcat
Affected versions
<9.0.118-3.166.1
suse/tomcat-admin-webapps
pkg:rpm/suse/tomcat-admin-webapps
Affected versions
<9.0.118-3.166.1
suse/tomcat-docs-webapp
pkg:rpm/suse/tomcat-docs-webapp
Affected versions
<9.0.118-3.166.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 00:59:42 UTC

Technical Analysis

This security advisory covers Red Hat JBoss Web Server 6.2.4, which addresses multiple vulnerabilities in Apache Tomcat components integrated within the server. The fixed issues include CVE-2026-41293 (HTTP/2 request headers not validated), CVE-2026-43514 (information disclosure via AJP secret timing discrepancy), CVE-2026-43512 (authentication bypass via digest authentication), CVE-2026-43513 (improper handling of case sensitivity in LockOutRealm), CVE-2026-43515 (improper authorization allowing security bypass), CVE-2026-42498 (information disclosure during WebSocket authentication), CVE-2026-41284 (denial of service due to uncontrolled resource allocation), CVE-2026-53404 (incorrect control flow in rewrite valve), and CVE-2026-55956 (improper authorization allowing security constraint bypass). These vulnerabilities affect the Apache Tomcat servlet container and related components bundled in Red Hat JBoss Web Server 6.2 on RHEL 8, 9, and 10. The update to version 6.2.4 includes bug fixes, enhancements, and component upgrades documented in the release notes. No known exploits in the wild have been reported at this time.

Potential Impact

The vulnerabilities fixed in this update could allow attackers to bypass authentication mechanisms, disclose sensitive information, cause denial of service conditions, and bypass security constraints in the affected Apache Tomcat components. These issues could impact the confidentiality, integrity, and availability of Java web applications hosted on Red Hat JBoss Web Server 6.2 prior to version 6.2.4.

Mitigation Recommendations

Red Hat has released Red Hat JBoss Web Server 6.2.4 as a replacement for version 6.2.3, which includes fixes for all listed vulnerabilities. Users should apply this update to remediate the security issues. Before applying the update, ensure all previously released errata relevant to the system have been applied. Detailed update instructions are available from Red Hat's official documentation. No additional mitigation steps are indicated beyond applying the official update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
SUSE-SU-2026:2299-1
Cve Count
7
Additional Cves
["CVE-2026-41293","CVE-2026-42498","CVE-2026-43512","CVE-2026-43513","CVE-2026-43514","CVE-2026-43515"]
Cvss Version
null

Threat ID: 6a27e9a88dd33fbd8516f3d4

Added to database: 06/09/2026, 10:23:36 UTC

Last enriched: 07/31/2026, 00:59:42 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 430

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses