[CLSA-2026:1786763497] tomcat: Fix of 2 CVEs
Type:
security
Severity:
Low
Release date:
2026-08-15 03:11:48 UTC
Description:
- CVE-2025-49125: require the request path to end at the mount point or continue past it with a /, instead of testing the mount point as a bare string prefix, so a PreResources or PostResources set mounted below the web application root can no longer be reached via an unexpected path that is not covered by the same security constraints; also strip a trailing / from webAppMount in all cases, as upstream does, so a resource set mounted on a path ending in / keeps resolving its nested paths under the stricter check - CVE-2026-55276: include the * and ** special roles and empty authorization constraints when generating the effective web.xml, so the logged descriptor no longer understates the security constraints that are actually in force
Updated packages:
  • tomcat-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
    sha:b90724bd68438a68151fc7b690fc7dc322e7939afe078dfc15b5e7270c3b1198
  • tomcat-admin-webapps-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
    sha:8e0744948e37d8f6ab826469239fc4c45c5f547e96a4f35d1d3fa2f9290b3d6b
  • tomcat-docs-webapp-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
    sha:3b341cd8e04ea171765f5b98b60716a42156b614098fdb3904a93ff7b6a3c45b
  • tomcat-el-3.0-api-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
    sha:0e2b3a6106b1e2f558c56dec8beae01cd67f51bb7a611f313e58b0a24a06a7e3
  • tomcat-jsp-2.3-api-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
    sha:0ffacf8c5bffb28a382ce044ad721c3078c198657e93a1e8859d7eb43222cd47
  • tomcat-lib-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
    sha:495b48567395a1c6b45436a69a19e90b94088e59376562f9ce6d09db4a74bcba
  • tomcat-servlet-4.0-api-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
    sha:53dff4571f6fea92bc91f973e074809ee17d9af181ff54cd15f4f682a65e8e38
  • tomcat-webapps-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
    sha:0b9d3b58f0df08edd1f67c3a8b3af9fd96079fbce57811e975deccf12b628456
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.