[CLSA-2026:1785885924] tomcat: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-04 23:25:35 UTC
Description:
- CVE-2026-34487: stop logging the Kubernetes service account bearer token in the cloud membership provider, dropping the request headers from the connection debug message and the token from the failed-connection exception message (upstream tomcat 9.0.117) - CVE-2026-55276: include the special roles * and ** and empty authorization constraints in the generated effective web.xml, so a logged effective web.xml no longer understates the security constraints that are in force (upstream tomcat 9.0.119)
Updated packages:
  • tomcat-9.0.87-3.el9_6.3.tuxcare.els13.noarch.rpm
    sha:5960e7c36600e51a3f066fb82f3c39f83d3d21f9a3cfc4d689ac5be99907ed10
  • tomcat-admin-webapps-9.0.87-3.el9_6.3.tuxcare.els13.noarch.rpm
    sha:beb5dfc1a3c0230ef06522e1b61273e34e2f515fe47055424084f305ec603906
  • tomcat-docs-webapp-9.0.87-3.el9_6.3.tuxcare.els13.noarch.rpm
    sha:30edf0fba8ae2c9f0fdcab6ddd40754758d35c20bfae107acf0f2d7da6f700ae
  • tomcat-el-3.0-api-9.0.87-3.el9_6.3.tuxcare.els13.noarch.rpm
    sha:5a2c44d56dc4e81b2ed9ce60de8f7c1f1a5a4aaf5e83043e9cabf86c0baa4ab7
  • tomcat-jsp-2.3-api-9.0.87-3.el9_6.3.tuxcare.els13.noarch.rpm
    sha:e3cf2ad1d9c7dddd93459172bff69d5b7c68ee0dd50bb0c7040faee75e6e33e8
  • tomcat-lib-9.0.87-3.el9_6.3.tuxcare.els13.noarch.rpm
    sha:57a6f049190d7b525e2460b4cb4cd165fb3c053cbbb9639d86fcd069e28f0799
  • tomcat-servlet-4.0-api-9.0.87-3.el9_6.3.tuxcare.els13.noarch.rpm
    sha:3e27fb0b2d08bfe585a5e22fd8db0534a6c5c035f10bcb40d02fac209bc137bb
  • tomcat-webapps-9.0.87-3.el9_6.3.tuxcare.els13.noarch.rpm
    sha:2511f4eb2c850973afa69eb8e0f970cc218859d838da951730262c400711b49d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.