Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
RHSA-2026:67163
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:67163
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:67163.json
JSON Data
https://api.test.osv.dev/v1/vulns/RHSA-2026:67163
Upstream
CVE (30)
CVE-2024-34750
CVE-2024-38286
CVE-2025-46701
CVE-2025-55668
CVE-2025-55754
CVE-2025-61795
CVE-2025-66614
CVE-2026-24733
CVE-2026-24880
CVE-2026-25854
CVE-2026-29145
CVE-2026-32990
CVE-2026-34483
CVE-2026-34487
CVE-2026-41284
CVE-2026-41293
CVE-2026-42498
CVE-2026-43512
CVE-2026-43513
CVE-2026-43514
CVE-2026-43515
CVE-2026-50229
CVE-2026-53404
CVE-2026-53434
CVE-2026-55276
CVE-2026-55955
CVE-2026-55956
CVE-2026-55957
CVE-2026-59083
CVE-2026-59084
Published
2026-09-14T10:10:22Z
Modified
2026-10-02T10:22:35Z
Severity
7.5 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: tomcat9 security update
Details
References
https://access.redhat.com/errata/RHSA-2026:67163
https://access.redhat.com/security/updates/classification/#important
https://bugzilla.redhat.com/show_bug.cgi?id=2457025
https://bugzilla.redhat.com/show_bug.cgi?id=2476511
https://bugzilla.redhat.com/show_bug.cgi?id=2476513
https://bugzilla.redhat.com/show_bug.cgi?id=2476516
https://bugzilla.redhat.com/show_bug.cgi?id=2476519
https://bugzilla.redhat.com/show_bug.cgi?id=2476520
https://bugzilla.redhat.com/show_bug.cgi?id=2494669
https://bugzilla.redhat.com/show_bug.cgi?id=2499917
https://bugzilla.redhat.com/show_bug.cgi?id=2499931
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67163.json
https://access.redhat.com/security/cve/CVE-2024-34750
https://bugzilla.redhat.com/show_bug.cgi?id=2295651
https://www.cve.org/CVERecord?id=CVE-2024-34750
https://nvd.nist.gov/vuln/detail/CVE-2024-34750
https://lists.apache.org/thread/4kqf0bc9gxymjc2x7v3p7dvplnl77y8l
https://access.redhat.com/security/cve/CVE-2024-38286
https://bugzilla.redhat.com/show_bug.cgi?id=2314686
https://www.cve.org/CVERecord?id=CVE-2024-38286
https://nvd.nist.gov/vuln/detail/CVE-2024-38286
https://lists.apache.org/thread/wms60cvbsz3fpbz9psxtfx8r41jl6d4s
https://access.redhat.com/security/cve/CVE-2025-46701
https://bugzilla.redhat.com/show_bug.cgi?id=2369253
https://www.cve.org/CVERecord?id=CVE-2025-46701
https://nvd.nist.gov/vuln/detail/CVE-2025-46701
https://lists.apache.org/thread/xhqqk9w5q45srcdqhogdk04lhdscv30j
https://access.redhat.com/security/cve/CVE-2025-55668
https://bugzilla.redhat.com/show_bug.cgi?id=2388226
https://www.cve.org/CVERecord?id=CVE-2025-55668
https://nvd.nist.gov/vuln/detail/CVE-2025-55668
https://github.com/apache/tomcat/commit/8621e4c6ba2c916a41eb34cb0f781171ead33fb6
https://github.com/apache/tomcat/commit/90306d971bb8b8393336d893644124fb2ca11d21
https://github.com/apache/tomcat/commit/9c3673ba04009377cb0c81ccb6cf5078aec1aa95
https://lists.apache.org/thread/v6bknr96rl7l1qxkl1c03v0qdvbbqs47
https://access.redhat.com/security/cve/CVE-2025-55754
https://bugzilla.redhat.com/show_bug.cgi?id=2406590
https://www.cve.org/CVERecord?id=CVE-2025-55754
https://nvd.nist.gov/vuln/detail/CVE-2025-55754
https://github.com/apache/tomcat/commit/5a3db092982c0c58d4855304167ee757fe5e79bb
https://lists.apache.org/thread/j7w54hqbkfcn0xb9xy0wnx8w5nymcbqd
https://access.redhat.com/security/cve/CVE-2025-61795
https://bugzilla.redhat.com/show_bug.cgi?id=2406588
https://www.cve.org/CVERecord?id=CVE-2025-61795
https://nvd.nist.gov/vuln/detail/CVE-2025-61795
https://github.com/apache/tomcat/commit/1cdf5f730ede75a0759492f179ac21ca4ff68e06
https://lists.apache.org/thread/wm9mx8brmx9g4zpywm06ryrtvd3160pp
https://access.redhat.com/security/cve/CVE-2025-66614
https://bugzilla.redhat.com/show_bug.cgi?id=2440430
https://www.cve.org/CVERecord?id=CVE-2025-66614
https://nvd.nist.gov/vuln/detail/CVE-2025-66614
https://lists.apache.org/thread/vw6lxtlh2qbqwpb61wd3sv1flm2nttw7
https://access.redhat.com/security/cve/CVE-2026-24733
https://bugzilla.redhat.com/show_bug.cgi?id=2440437
https://www.cve.org/CVERecord?id=CVE-2026-24733
https://nvd.nist.gov/vuln/detail/CVE-2026-24733
https://lists.apache.org/thread/6xk3t65qpn1myp618krtfotbjn1qt90f
https://access.redhat.com/security/cve/CVE-2026-24880
https://bugzilla.redhat.com/show_bug.cgi?id=2457040
https://www.cve.org/CVERecord?id=CVE-2026-24880
https://nvd.nist.gov/vuln/detail/CVE-2026-24880
https://lists.apache.org/thread/2c682qnlg2tv4o5knlggqbl9yc2gb5sn
https://access.redhat.com/security/cve/CVE-2026-25854
https://bugzilla.redhat.com/show_bug.cgi?id=2457039
https://www.cve.org/CVERecord?id=CVE-2026-25854
https://nvd.nist.gov/vuln/detail/CVE-2026-25854
https://lists.apache.org/thread/ghct3b6o74bp2vm7q875s1zh0dqrz3h0
https://access.redhat.com/security/cve/CVE-2026-29145
https://bugzilla.redhat.com/show_bug.cgi?id=2457037
https://www.cve.org/CVERecord?id=CVE-2026-29145
https://nvd.nist.gov/vuln/detail/CVE-2026-29145
https://lists.apache.org/thread/yz5fxmhd2j43wgqykssdo7kltws57jfz
https://access.redhat.com/security/cve/CVE-2026-32990
https://www.cve.org/CVERecord?id=CVE-2026-32990
https://nvd.nist.gov/vuln/detail/CVE-2026-32990
https://lists.apache.org/thread/1nl9zqft0ksqlhlkd3j4obyjz1ghoyn7
https://access.redhat.com/security/cve/CVE-2026-34483
https://bugzilla.redhat.com/show_bug.cgi?id=2457044
https://www.cve.org/CVERecord?id=CVE-2026-34483
https://nvd.nist.gov/vuln/detail/CVE-2026-34483
https://lists.apache.org/thread/j1w7304yonlr8vo1tkb5nfs7od1y228b
https://access.redhat.com/security/cve/CVE-2026-34487
https://bugzilla.redhat.com/show_bug.cgi?id=2457038
https://www.cve.org/CVERecord?id=CVE-2026-34487
https://nvd.nist.gov/vuln/detail/CVE-2026-34487
https://lists.apache.org/thread/4xpkwolpkrj8v5xzp5nyovtlqp3y850h
https://access.redhat.com/security/cve/CVE-2026-41284
https://bugzilla.redhat.com/show_bug.cgi?id=2476518
https://www.cve.org/CVERecord?id=CVE-2026-41284
https://nvd.nist.gov/vuln/detail/CVE-2026-41284
https://lists.apache.org/thread/2nvqjr7ovjmvx2vbhb7s61ycd5msc8qc
https://access.redhat.com/security/cve/CVE-2026-41293
https://www.cve.org/CVERecord?id=CVE-2026-41293
https://nvd.nist.gov/vuln/detail/CVE-2026-41293
https://lists.apache.org/thread/qwg0q16z7xkb2qrr853wdll5531mvl1r
https://access.redhat.com/security/cve/CVE-2026-42498
https://www.cve.org/CVERecord?id=CVE-2026-42498
https://nvd.nist.gov/vuln/detail/CVE-2026-42498
https://lists.apache.org/thread/n61zwf75jrv09rz90j4jssncm244bwdb
https://access.redhat.com/security/cve/CVE-2026-43512
https://www.cve.org/CVERecord?id=CVE-2026-43512
https://nvd.nist.gov/vuln/detail/CVE-2026-43512
https://lists.apache.org/thread/7x09x7o12solvclslw3sz0288xc8wx73
https://access.redhat.com/security/cve/CVE-2026-43513
https://www.cve.org/CVERecord?id=CVE-2026-43513
https://nvd.nist.gov/vuln/detail/CVE-2026-43513
https://lists.apache.org/thread/ytjcgldshj73lcnd1sh95od5hrghwogp
https://access.redhat.com/security/cve/CVE-2026-43514
https://bugzilla.redhat.com/show_bug.cgi?id=2476512
https://www.cve.org/CVERecord?id=CVE-2026-43514
https://nvd.nist.gov/vuln/detail/CVE-2026-43514
https://lists.apache.org/thread/2k654v5cq123npfsd1b2kk1y30owqb1m
https://access.redhat.com/security/cve/CVE-2026-43515
https://www.cve.org/CVERecord?id=CVE-2026-43515
https://nvd.nist.gov/vuln/detail/CVE-2026-43515
https://lists.apache.org/thread/746nxfxod0wsocxtmv8pb8nkgmwpc6bb
https://access.redhat.com/security/cve/CVE-2026-50229
https://bugzilla.redhat.com/show_bug.cgi?id=2494688
https://www.cve.org/CVERecord?id=CVE-2026-50229
https://nvd.nist.gov/vuln/detail/CVE-2026-50229
https://lists.apache.org/thread/wlt2no8bw45zl1w8byop4zfqphldf5j0
https://access.redhat.com/security/cve/CVE-2026-53404
https://bugzilla.redhat.com/show_bug.cgi?id=2494681
https://www.cve.org/CVERecord?id=CVE-2026-53404
https://nvd.nist.gov/vuln/detail/CVE-2026-53404
https://lists.apache.org/thread/rdhpghgfskrdmw9hqzjgjrtw538smpmz
https://access.redhat.com/security/cve/CVE-2026-53434
https://bugzilla.redhat.com/show_bug.cgi?id=2494668
https://www.cve.org/CVERecord?id=CVE-2026-53434
https://nvd.nist.gov/vuln/detail/CVE-2026-53434
https://lists.apache.org/thread/x510lbq0sfrd1qyo7q3r1mpllgpdcosk
https://access.redhat.com/security/cve/CVE-2026-55276
https://bugzilla.redhat.com/show_bug.cgi?id=2494675
https://www.cve.org/CVERecord?id=CVE-2026-55276
https://nvd.nist.gov/vuln/detail/CVE-2026-55276
https://lists.apache.org/thread/jy09xjlzn6r2qwvqoph8vcmf959yq68v
https://access.redhat.com/security/cve/CVE-2026-55955
https://bugzilla.redhat.com/show_bug.cgi?id=2494678
https://www.cve.org/CVERecord?id=CVE-2026-55955
https://nvd.nist.gov/vuln/detail/CVE-2026-55955
https://lists.apache.org/thread/g4p5sf45p3f9r011pwqs9r54yd64s106
https://access.redhat.com/security/cve/CVE-2026-55956
https://bugzilla.redhat.com/show_bug.cgi?id=2494676
https://www.cve.org/CVERecord?id=CVE-2026-55956
https://nvd.nist.gov/vuln/detail/CVE-2026-55956
https://lists.apache.org/thread/dcjdcnnnww9hhdm016hr0l7hpw1bzjfp
https://access.redhat.com/security/cve/CVE-2026-55957
https://www.cve.org/CVERecord?id=CVE-2026-55957
https://nvd.nist.gov/vuln/detail/CVE-2026-55957
https://lists.apache.org/thread/7fk339o5jvd4mcgsf0chbrn4o525ccjh
https://access.redhat.com/security/cve/CVE-2026-59083
https://www.cve.org/CVERecord?id=CVE-2026-59083
https://nvd.nist.gov/vuln/detail/CVE-2026-59083
https://lists.apache.org/thread/3g63zos2gkjo5vgnrk8kxmosv47w6wbq
https://access.redhat.com/security/cve/CVE-2026-59084
https://www.cve.org/CVERecord?id=CVE-2026-59084
https://nvd.nist.gov/vuln/detail/CVE-2026-59084
https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7
Affected packages
Red Hat:enterprise_linux_eus:10.0
tomcat9
Package
Name
tomcat9
Purl
pkg:rpm/redhat/tomcat9
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.120-1.el10_0
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67163.json"
tomcat9-admin-webapps
Package
Name
tomcat9-admin-webapps
Purl
pkg:rpm/redhat/tomcat9-admin-webapps
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.120-1.el10_0
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67163.json"
tomcat9-docs-webapp
Package
Name
tomcat9-docs-webapp
Purl
pkg:rpm/redhat/tomcat9-docs-webapp
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.120-1.el10_0
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67163.json"
tomcat9-el-3.0-api
Package
Name
tomcat9-el-3.0-api
Purl
pkg:rpm/redhat/tomcat9-el-3.0-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.120-1.el10_0
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67163.json"
tomcat9-jsp-2.3-api
Package
Name
tomcat9-jsp-2.3-api
Purl
pkg:rpm/redhat/tomcat9-jsp-2.3-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.120-1.el10_0
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67163.json"
tomcat9-lib
Package
Name
tomcat9-lib
Purl
pkg:rpm/redhat/tomcat9-lib
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.120-1.el10_0
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67163.json"
tomcat9-servlet-4.0-api
Package
Name
tomcat9-servlet-4.0-api
Purl
pkg:rpm/redhat/tomcat9-servlet-4.0-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.120-1.el10_0
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67163.json"
tomcat9-webapps
Package
Name
tomcat9-webapps
Purl
pkg:rpm/redhat/tomcat9-webapps
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.120-1.el10_0
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67163.json"
RHSA-2026:67163 - OSV