Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

tomcat-9.0.120-1.el9 RPM for noarch

From CentOS Stream 9 AppStream for x86_64

Name: tomcat Distribution: CentOS
Version: 9.0.120 Vendor: CentOS
Release: 1.el9 Build date: Fri Sep 4 18:50:52 2026
Group: Unspecified Build host: s390-07.stream.rdu2.redhat.com
Size: 332253 Source RPM: tomcat-9.0.120-1.el9.src.rpm
Packager: builder@centos.org
Url: http://tomcat.apache.org/
Summary: Apache Servlet/JSP Engine, RI for Servlet 4.0/JSP 2.3 API
Tomcat is the servlet container that is used in the official Reference
Implementation for the Java Servlet and JavaServer Pages technologies.
The Java Servlet and JavaServer Pages specifications are developed by
Sun under the Java Community Process.

Tomcat is developed in an open and participatory environment and
released under the Apache Software License version 2.0. Tomcat is intended
to be a collaboration of the best-of-breed developers from around the world.

Provides

Requires

License

ASL 2.0

Changelog

* Thu Jun 04 2026 Pietro Meloni <pmeloni@redhat.com> - 1:9.0.120-1
  - Resolves: RHEL-192824 tomcat: HTTP/2 request headers not validated (CVE-2026-41293)
  - Resolves: RHEL-192661 tomcat: Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990)
  - Resolves: RHEL-219555 tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083)
  - Resolves: RHEL-219578 tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084)
  - Resolves: RHEL-238190 tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498)
  - Resolves: RHEL-238248 tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513)
  - Resolves: RHEL-238272 tomcat: Improper Authorization allows security bypass (CVE-2026-43515)
  - Resolves: RHEL-238303 tomcat: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512)
* Thu Jun 04 2026 Pietro Meloni <pmeloni@redhat.com> - 1:9.0.117-2
  - Resolves: RHEL-183992 Remove tomcat clustering JAR from RPM builds
  - Exclude i686 architecture from build
* Tue May 26 2026 Pietro Meloni <pmeloni@redhat.com> - 1:9.0.117-1
  - Resolves: RHEL-150714 Certificate revocation bypass due to improper OCSP response validation
  - Resolves:
    Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled (CVE-2026-34500)
  - Resolves:
    Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token (CVE-2026-34487)
  - Resolves:
    Tomcat: The fix for CVE-2026-29146 allowed the bypass of the EncryptInterceptor (CVE-2026-34486)
  - Resolves:
    Tomcat: Incomplete escaping of JSON access logs (CVE-2026-34483)
  - Resolves:
    Tomcat: The fix for CVE-2025-66614 was incomplete (CVE-2026-32990)
  - Resolves:
    Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default (CVE-2026-29146)
  - Resolves:
    Tomcat: OCSP checks sometimes soft-fail even when soft-fail is disabled (CVE-2026-29145)
  - Resolves:
    Tomcat: Configured TLS cipher preference order not preserved (CVE-2026-29129)
  - Resolves:
    Tomcat: Occasionally open redirect (CVE-2026-25854)
  - Resolves:
    Tomcat: Request smuggling via invalid chunk extension (CVE-2026-24880)
  - Resolves:
    Tomcat: Incomplete OCSP verification checks (CVE-2026-24734)
  - Resolves:
    Tomcat: Security constraint bypass (CVE-2026-24733)
  - Resolves:
    Tomcat: Client certificate verification bypass due to virtual host mapping (CVE-2025-66614)
* Tue Apr 14 2026 Coty Sutherland <csutherl@redhat.com> - 1:9.0.110-3
  - Resolves: RHEL-168081 Fix copy/paste error in AJP connector that caused DELETE requests to be processed as OPTIONS requests (BZ#69848)
* Thu Feb 26 2026 Coty Sutherland <csutherl@redhat.com> - 1:9.0.110-2
  - Resolves: RHEL-154364 Tomcat fails to respond to client connections when using Java 8
* Wed Feb 11 2026 Coty Sutherland <csutherl@redhat.com> - 1:9.0.110-1
  - Resolves: RHEL-148687
    Update to 9.0.110 and compile with Java 25 to enable FFM features for PQC support
* Wed Jan 21 2026 Pietro Meloni <pmeloni@redhat.com> - 1:9.0.87-7
  - Resolves: RHEL-124516
    tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752)
  - Resolves: RHEL-132561
    tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651)
* Thu Aug 14 2025 Adam Krajcik <akrajcik@redhat.com> - 1:9.0.87-6
  - Resolves: RHEL-102201
    tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames (CVE-2025-48989)