Red Hat Security Advisory: Red Hat JBoss Web Server 6.2.2 release and security update
Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. This release of Red Hat JBoss Web Server 6.2.2 serves as a replacement for Red Hat JBoss Web Server 6.2.1. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section. Security Fix(es): * tomcat: security constraint bypass with HTTP/0.9 (CVE-2026-24733) * tomcat: Client certificate verification bypass due to virtual host mapping (CVE-2025-66614) * tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
This vulnerability in Apache Tomcat involves improper input validation related to the TLS Server Name Indication (SNI) extension and the HTTP Host header. When Tomcat is configured with multiple virtual hosts where some require client certificate authentication and others do not, an attacker can bypass client certificate authentication by sending different hostnames in the SNI extension and the HTTP Host header. The issue affects multiple versions across Tomcat 8.5, 9.0, 10.1, and 11.0 branches. The vulnerability is mitigated by upgrading to fixed versions 11.0.15+, 10.1.50+, or 9.0.113+.
Potential Impact
An attacker can bypass client certificate authentication in configurations where it is enforced only at the Connector level and multiple virtual hosts have differing client certificate requirements. This could allow unauthorized access to resources protected by client certificate authentication, leading to potential confidentiality and integrity impacts. The CVSS vector indicates network attack vector, low attack complexity, no privileges required, no user interaction, with high confidentiality and integrity impact but no availability impact.
Mitigation Recommendations
Users should upgrade affected Apache Tomcat versions to 11.0.15 or later, 10.1.50 or later, or 9.0.113 or later, which include the fix for this vulnerability. If upgrading is not immediately possible, ensure that client certificate authentication is enforced at the web application level rather than only at the Connector level to mitigate the risk. Patch status is confirmed by the vendor advisory recommending these fixed versions.
Red Hat Security Advisory: Red Hat JBoss Web Server 6.2.2 release and security update
Description
Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. This release of Red Hat JBoss Web Server 6.2.2 serves as a replacement for Red Hat JBoss Web Server 6.2.1. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section. Security Fix(es): * tomcat: security constraint bypass with HTTP/0.9 (CVE-2026-24733) * tomcat: Client certificate verification bypass due to virtual host mapping (CVE-2025-66614) * tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
pkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Apache Tomcat involves improper input validation related to the TLS Server Name Indication (SNI) extension and the HTTP Host header. When Tomcat is configured with multiple virtual hosts where some require client certificate authentication and others do not, an attacker can bypass client certificate authentication by sending different hostnames in the SNI extension and the HTTP Host header. The issue affects multiple versions across Tomcat 8.5, 9.0, 10.1, and 11.0 branches. The vulnerability is mitigated by upgrading to fixed versions 11.0.15+, 10.1.50+, or 9.0.113+.
Potential Impact
An attacker can bypass client certificate authentication in configurations where it is enforced only at the Connector level and multiple virtual hosts have differing client certificate requirements. This could allow unauthorized access to resources protected by client certificate authentication, leading to potential confidentiality and integrity impacts. The CVSS vector indicates network attack vector, low attack complexity, no privileges required, no user interaction, with high confidentiality and integrity impact but no availability impact.
Mitigation Recommendations
Users should upgrade affected Apache Tomcat versions to 11.0.15 or later, 10.1.50 or later, or 9.0.113 or later, which include the fix for this vulnerability. If upgrading is not immediately possible, ensure that client certificate authentication is enforced at the web application level rather than only at the Connector level to mitigate the risk. Patch status is confirmed by the vendor advisory recommending these fixed versions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2025-66614
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a58b50368715ace43db286f
Added to database: 07/16/2026, 10:40:03 UTC
Last enriched: 07/30/2026, 11:23:10 UTC
Last updated: 08/05/2026, 00:41:10 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.