Red Hat Product Errata RHSA-2026:43402 - Security Advisory Issued: 2026-07-22 Updated: 2026-07-22 RHSA-2026:43402 - Security Advisory Overview Synopsis Important: Red Hat JBoss Web Server 6.2.4 release and security update Type/Severity Security Advisory: Important Topic Red Hat JBoss Web Server 6.2.4 zip release is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, and Windows Server. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. This release of Red Hat JBoss Web Server 6.2.4 serves as a replacement for Red Hat JBoss Web Server 6.2.3. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section. Security Fix(es): tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293) tomcat-coyote: Apache Tomcat: Information disclosure via AJP secret timing discrepancy (CVE-2026-43514) tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512) tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) tomcat-coyote: tomcat: Improper Authorization allows security bypass (CVE-2026-43515) tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498) tomcat-catalina: Apache Tomcat: Denial of Service due to uncontrolled resource allocation (CVE-2026-41284) tomcat-catalina: Apache Tomcat: Incorrect control flow in rewrite valve allows unexpected rule processing (CVE-2026-53404) tomcat-catalina: Apache Tomcat: Improper Authorization Allows Security Constraint Bypass (CVE-2026-55956) openssl.exe: OpenSSL TLS 1.3 server may choose unexpected key agreement group (CVE-2026-2673) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution Before applying the update, back up your existing Red Hat JBoss Web Server installation, including all applications and configuration files. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Affected Products JBoss Enterprise Web Server Text-Only Advisories x86_64 Fixes BZ - 2447327 - CVE-2026-2673 openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement group BZ - 2476511 - CVE-2026-43512 tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication BZ - 2476512 - CVE-2026-43514 tomcat-coyote: Apache Tomcat: Information disclosure via AJP secret timing discrepancy BZ - 2476513 - CVE-2026-41293 tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated BZ - 2476516 - CVE-2026-42498 tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. BZ - 2476518 - CVE-2026-41284 tomcat: Apache Tomcat: Denial of Service due to uncontrolled resource allocation BZ - 2476519 - CVE-2026-43515 tomcat-coyote: tomcat: Improper Authorization allows security bypass BZ - 2476520 - CVE-2026-43513 tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm BZ - 2494676 - CVE-2026-55956 tomcat: Apache Tomcat: Improper Authorization Allows Security Constraint Bypass BZ - 2494681 - CVE-2026-53404 Apache Tomcat: Apache Tomcat: Incorrect control flow in rewrite valve allows unexpected rule processing CVEs CVE-2026-2673 CVE-2026-41284 CVE-2026-41293 CVE-2026-42498 CVE-2026-43512 CVE-2026-43513 CVE-2026-43514 CVE-2026-43515 CVE-2026-53404 CVE-2026-55956 References https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en/documentation/red_hat_jboss_web_server/6.2/html/red_hat_jboss_web_server_6.2_service_pack_4_release_notes/index The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This security update for Red Hat JBoss Web Server 6.2.4 addresses multiple vulnerabilities in its Apache Tomcat components, including critical flaws such as unvalidated HTTP/2 request headers (CVE-2026-41293, CVSS 9.8) and an authentication bypass via digest authentication (CVE-2026-43512, CVSS 9.8). Affected Tomcat versions include 9.0.0 to 9.0.117, 10.1.0 to 10.1.54, and 11.0.0 to 11.0.21, which are resolved by upgrading to Tomcat 9.0.118, 10.1.55, or 11.0.22 respectively. The advisory recommends backing up installations before applying the provided JBoss Web Server 6.2.4 update.