Release date:
2026-08-07 16:55:45 UTC
Description:
- CVE-2026-24880: validate HTTP/1.1 chunk extensions with a new ChunkExtension state
machine instead of skipping them unparsed, so a CRLF embedded in a quoted extension
value can no longer desync Tomcat from a front-end proxy and smuggle a request
- CVE-2026-25854: collapse leading slashes on the request URI and redirect via
sendRedirect in the LoadBalancerDrainingValve so a protocol-relative URI can no
longer be reflected into the Location header as an open redirect
- CVE-2026-34483: escape the request URI and query string in the access log %r, %q
and %U elements so log fields cannot be forged through unescaped output
- CVE-2026-34487: stop logging the Kubernetes bearer token by dropping it from the
tokenStream.failedConnection message and dropping the request headers from the
cloud stream provider debug log
Updated packages:
-
tomcat-9.0.62-12.el9_2.1.tuxcare.els8.noarch.rpm
sha:cc52540c02ac7e1c7c6b3047bb4f892ead273d83edad99cb52f67ad06197214f
-
tomcat-admin-webapps-9.0.62-12.el9_2.1.tuxcare.els8.noarch.rpm
sha:efe6c0641210f81a0fa59bbe4cb7d9654eb9befa7a2c6ebbee7b70a06a15cd91
-
tomcat-docs-webapp-9.0.62-12.el9_2.1.tuxcare.els8.noarch.rpm
sha:64a22d3c18d7af25e334f413056a0bb5e408f67472c96c13caeedae6634df491
-
tomcat-el-3.0-api-9.0.62-12.el9_2.1.tuxcare.els8.noarch.rpm
sha:afc7c16e360fce833a3bd4f17ab90856fa3eeed131315b9ba9f2facb6b4f97b2
-
tomcat-jsp-2.3-api-9.0.62-12.el9_2.1.tuxcare.els8.noarch.rpm
sha:a2c67ca05f151e51d90fe90e4ecc7b9f15b946530c42cd5f7c4afd3997abec5c
-
tomcat-lib-9.0.62-12.el9_2.1.tuxcare.els8.noarch.rpm
sha:8a812f7ca35097fb593124f9b851fa4e1629fee6f59df73ad271eb0ec5b1abe9
-
tomcat-servlet-4.0-api-9.0.62-12.el9_2.1.tuxcare.els8.noarch.rpm
sha:894c8cef6cf316d04720e67877a75d90b90b2223479e0a7f93c26da7ffe95984
-
tomcat-webapps-9.0.62-12.el9_2.1.tuxcare.els8.noarch.rpm
sha:1769e5ebfda778d965ed357c1275a14059e1bdf68c7976465bff119af7d46075
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.