Skip to main content

Threats Tagged 'cve-2026-68525'

View all threats tagged with 'cve-2026-68525'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-68525

Threats Tagged 'cve-2026-68525'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat has issued a security advisory for Red Hat Hardened Images RPMs, including updates to tomcat10 and tomcat11 packages. This update addresses multiple vulnerabilities identified by several CVEs including CVE-2026-65182 and others. The advisory provides updated RPM packages with bug fixes and enhancements. A patch is available for affected versions. No active exploits in the wild are reported at this time.

Join the discussion

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. This release of Red Hat JBoss Web Server 6.2.5 serves as a replacement for Red Hat JBoss Web Server 6.2.4. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section. Security Fix(es): * tomcat-catalina: Apache Tomcat: Misleading security logs due to incorrect control flow (CVE-2026-55276) * tomcat-coyote-ffm: Apache Tomcat: Error condition not handled when configuring CRL (CVE-2026-53434) * jws6-tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) * tomcat: Apache Tomcat: Local information disclosure via Unix domain socket TOCTOU race condition (CVE-2026-65183) * tomcat: Apache Tomcat: Security constraint bypass due to improper access control (CVE-2026-65182) * tomcat: Apache Tomcat: Access control bypass due to off-by-one error in RewriteValve [N] flag processing (CVE-2026-65927) * tomcat: Apache Tomcat: Denial of Service via HTTP/2 allocation leak (CVE-2026-68763) * tomcat: Apache Tomcat: Unauthorized resource access via FORM authentication bypass (CVE-2026-68525) * tomcat: Apache Tomcat - DoS in WebSocket chat example (CVE-2026-66299) * tomcat: Apache Tomcat: Authenticated WebSocket session persists after HTTP session termination (CVE-2026-73180) * tomcat: Apache Tomcat: Improper Authorization allows bypass of declarative role constraints (CVE-2026-66422) * tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure (CVE-2026-68569) * tomcat: Apache Tomcat: Authentication bypass via limited replay attack in DIGEST authenticator (CVE-2026-65905) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. This release of Red Hat JBoss Web Server 6.2.5 serves as a replacement for Red Hat JBoss Web Server 6.2.4. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section. Security Fix(es): * tomcat-catalina: Apache Tomcat: Misleading security logs due to incorrect control flow (CVE-2026-55276) * tomcat-coyote-ffm: Apache Tomcat: Error condition not handled when configuring CRL (CVE-2026-53434) * jws6-tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) * tomcat: Apache Tomcat: Local information disclosure via Unix domain socket TOCTOU race condition (CVE-2026-65183) * tomcat: Apache Tomcat: Security constraint bypass due to improper access control (CVE-2026-65182) * tomcat: Apache Tomcat: Access control bypass due to off-by-one error in RewriteValve [N] flag processing (CVE-2026-65927) * tomcat: Apache Tomcat: Denial of Service via HTTP/2 allocation leak (CVE-2026-68763) * tomcat: Apache Tomcat: Unauthorized resource access via FORM authentication bypass (CVE-2026-68525) * tomcat: Apache Tomcat - DoS in WebSocket chat example (CVE-2026-66299) * tomcat: Apache Tomcat: Authenticated WebSocket session persists after HTTP session termination (CVE-2026-73180) * tomcat: Apache Tomcat: Improper Authorization allows bypass of declarative role constraints (CVE-2026-66422) * tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure (CVE-2026-68569) * tomcat: Apache Tomcat: Authentication bypass via limited replay attack in DIGEST authenticator (CVE-2026-65905) * openssl.exe: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447) * jws-optional-native-components-win6-x86_64.zip: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (CVE-2026-34181) * jws-optional-native-components-win6-x86_64.zip: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure (CVE-2026-34180) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Multiple security vulnerabilities have been identified and fixed in Apache Tomcat as distributed by Red Hat. These include improper input validation, authentication bypass, HTTP/2 header validation issues, information disclosure during WebSocket authentication, improper authorization, case sensitivity handling flaws, and security constraint bypasses. The update addresses these issues in Red Hat Enterprise Linux versions 10.1.0 up to but not including 10.1.49. The vulnerabilities collectively have a moderate security impact.

Join the discussion

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990) * tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512) * tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293) * tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. (CVE-2026-42498) * tomcat-coyote: tomcat: Improper Authorization allows security bypass (CVE-2026-43515) * tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) * tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) * tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084) Bug Fix(es) and Enhancement(s): * Tomcat fails to respond to client connections when using Java 8 [rhel-9.8] (JIRA:RHEL-257456) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

This security update for Tomcat 11 addresses multiple vulnerabilities including security constraint bypass, TOCTOU issues with Unix Domain Socket permissions, incomplete HTTP/2 SNI validation fixes, replay attacks with DIGEST authentication, access control bypasses, memory exhaustion via WebSocket, role reference bypasses, and denial-of-service via HTTP/2 stream reset. The update also includes fixes for session management, authentication, and configuration parsing errors. These vulnerabilities collectively pose risks of unauthorized access, denial of service, and potential privilege escalation. The update corresponds to Tomcat version 11.0.25.

Join the discussion

CVE-2026-68525 is a critical incorrect authorization vulnerability in Apache Tomcat's FORM authentication process. It allows bypassing a security constraint that restricts user access to a resource's POST method but not its GET method. This affects multiple Apache Tomcat versions including 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, and 9.0.0.M1 through 9.0.120, as well as some end-of-life versions. The issue is fixed in versions 11.0.25, 10.1.58, and 9.0.121.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: cve-2026-68525
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses