Red Hat Product Errata RHSA-2026:39188 - Security Advisory Issued: 2026-07-14 Updated: 2026-07-14 RHSA-2026:39188 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat JBoss Web Server 7.0.0 security release Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic Red Hat JBoss Web Server 7.0 is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, and Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. This release of Red Hat JBoss Web Server 7.0.0 serves as a replacement for Red Hat JBoss Web Server 6.2.3. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section. Security fix(es): tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass (CVE-2026-34486) tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor (CVE-2026-29146) tomcat-coyote: tomcat: Improper Authorization allows security bypass (CVE-2026-43515) tomcat-catalina: Apache Tomcat: Denial of Service due to uncontrolled resource allocation (CVE-2026-41284) tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293) tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498) tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512) tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) tomcat-coyote: Apache Tomcat: Information disclosure via AJP secret timing discrepancy (CVE-2026-43514) tomcat-catalina: Apache Tomcat: Improper Authorization Allows Security Constraint Bypass (CVE-2026-55956) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Affected Products JBoss Enterprise Web Server 7 for RHEL 10 x86_64 JBoss Enterprise Web Server 7 for RHEL 9 x86_64 JBoss Enterprise Web Server 7 for RHEL 8 x86_64 Fixes BZ - 2457020 - CVE-2026-29146 Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor BZ - 2457027 - CVE-2026-34486 Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass BZ - 2476511 - CVE-2026-43512 tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication BZ - 2476512 - CVE-2026-43514 tomcat-coyote: Apache Tomcat: Information disclosure via AJP secret timing discrepancy BZ - 2476513 - CVE-2026-41293 tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated BZ - 2476516 - CVE-2026-42498 tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. BZ - 2476519 - CVE-2026-43515 tomcat-coyote: tomcat: Improper Authorization allows security bypass BZ - 2476520 - CVE-2026-43513 tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm BZ - 2494676 - CVE-2026-55956 tomcat: Apache Tomcat: Improper Authorization Allows Security Constraint Bypass CVEs CVE-2026-29146 CVE-2026-34486 CVE-2026-41284 CVE-2026-41293 CVE-2026-42498 CVE-2026-43512 CVE-2026-43513 CVE-2026-43514 CVE-2026-43515 CVE-2026-55956 References https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en/documentation/red_hat_jboss_web_server/7.0/html/red_hat_jboss_web_server_7.0_release_notes/index Note: More recent versions of these packages may be available. Click a package name for more details. JBoss Enterprise Web Server 7 for RHEL 10 SRPM jws7-ecj-4.38.0-1.redhat_00001.1.el10jws.src.rpm SHA-256: 3c065768fbce99b758fa714613134677978e1571eecc9d0f638f29bdc2417047 jws7-javapackages-tools-6.0.0-1.el10jws.src.rpm SHA-256: 20890b2e04a41f33cde9564ff5d03e797d9be700b90018ff9ae2d44361daeda8 jws7-jboss-logging-3.6.2-1.Final_redhat_00001.1.el10jws.src.rpm SHA-256: 178c44eb52941ff7f56bc1e3911cddaf92f2a5b8dbca1728462b1759eb8ad160 jws7-mod_cluster-2.1.0-1.Final_redhat_00001.1.el10jws.src.rpm SHA-256: 8b7729494a8ebca8efc6353c769245036299bb23d5941617bf1c4b9390157d35 jws7-tomcat-11.0.21-5.redhat_00004.1.el10jws.src.rpm SHA-256: 569b1b33a3c2a9efbe0b21a9fd83b8591c0b2e35ce88b34d96bc8642c46568cc jws7-tomcat-native-1.3.7-2.redhat_2.el10jws.src.rpm SHA-256: 9392a0687046d1a4012c6b740070885c49418fe53646586abc535cdfa0588110 jws7-tomcat-vault-1.1.11-4.Final_redhat_00003.1.el10jws.src.rpm SHA-256: 37dd5e831e978e4df158c055797ded3dd4e051aa90a0a7a2dfc4f33939056a21 x86_64 jws7-build-1-1.el10jws.x86_64.rpm SHA-256: 3ad1936944b81b64a6cdf2e31043162dc7a69b51f5a48c1da73d87d9761e4b63 jws7-ecj-4.38.0-1.redhat_00001.1.el10jws.noarch.rpm SHA-256: 7cb2fd886f46ee6e9b9e51461b7d223aff01a263177755d7b3e7f21e99c999ed jws7-javapackages-filesystem-6.0.0-1.el10jws.noarch.rpm SHA-256: c75bcbec184b68f50bf05ab5299cdc1f3dfc3278cdb32ff5538393fb966cc260 jws7-javapackages-tools-6.0.0-1.el10jws.noarch.rpm SHA-256: 6078885ae7dd3378d0b4ef6e9a3da93fc805bf15bcc9a785512405d7e7e81f67 jws7-jboss-logging-3.6.2-1.Final_redhat_00001.1.el10jws.noarch.rpm SHA-256: ad642b9a0de0b1a69dab6231b90a498e450eee4ad8afcf2dc69af27611990ac3 jws7-mod_cluster-2.1.0-1.Final_redhat_00001.1.el10jws.noarch.rpm SHA-256: 99e181afc0e32ddc3403c1c0d2cb267412a85f409b29b3f05b6356669e7a1945 jws7-mod_cluster-tomcat-2.1.0-1.Final_redhat_00001.1.el10jws.noarch.rpm SHA-256: 3f608904fcbddc4c63f50a542e260edab3c7f370c25d976c05488c6eccf2c996 jws7-python3-javapackages-6.0.0-1.el10jws.noarch.rpm SHA-256: 78d37bc517fb310901d7499f479cf8670995ba6e61e70a49f3446b1017b7ec96 jws7-runtime-1-1.el10jws.x86_64.rpm SHA-256: 157ff1103a249a1e80402a79602c737116546935e82343a7a681352f8407f26c jws7-tomcat-11.0.21-5.redhat_00004.1.el10jws.noarch.rpm SHA-256: 5dfaaf33db2408b310cb2414ddad1fd055582bb195adaa2852ed50210b52d1ee jws7-tomcat-admin-webapps-11.0.21-5.redhat_00004.1.el10jws.noarch.rpm SHA-256: a2ce567e2b134d31f15bdfdac4a09b6ee1d4a6efb0656f35d7f955e2aad78df6 jws7-tomcat-docs-webapp-11.0.21-5.redhat_00004.1.el10jws.noarch.rpm SHA-256: b98672f71a6b3ec201578147a327d468fe3b0b62c7fa257bd24a3da49df9997d jws7-tomcat-el-5.0-api-11.0.21-5.redhat_00004.1.el10jws.noarch.rpm SHA-256: 6b673f902e15171c6b24311c63669ef171843b9ea35083b544bd21010d4bcc6b jws7-tomcat-javadoc-11.0.21-5.redhat_00004.1.el10jws.noarch.rpm SHA-256: c7de0a03081eaec84117301f9b3ede7e7144d745fdfd0082919e89e46486f19f jws7-tomcat-jsp-3.1-api-11.0.21-5.redhat_00004.1.el10jws.noarch.rpm SHA-256: bd2d7b60c0954c7edbda98cfcddb7451a806a49d8cf8d22e4fd3b19a1ce5a2d0 jws7-tomcat-lib-11.0.21-5.redhat_00004.1.el10jws.noarch.rpm SHA-256: 27db39b3efd64d8bfe63a3a1d4c3d67b4f116954e490e03c6b9f7efcbffe422f jws7-tomcat-native-1.3.7-2.redhat_2.el10jws.x86_64.rpm SHA-256: 27b2a27bc0e5e87662c1c476113ad0c046d44346e4b4c1321bc2c18c6312fae8 jws7-tomcat-native-debuginfo-1.3.7-2.redhat_2.el10jws.x86_64.rpm SHA-256: 2ff1d62f4e2fc394123bb9fad83e7225438da37e5162c1a8e571a1b9ece903ee jws7-tomcat-selinux-11.0.21-5.redhat_00004.1.el10jws.noarch.rpm SHA-256: 003a1698e43b591599d23fbd611fda8ebaa5a7fd92cf08c3548c9b8110617512 jws7-tomcat-servlet-6.0-api-11.0.21-5.redhat_00004.1.el10jws.noarch.rpm SHA-256: f9ab21cb23a910f8fc212dc36946bd87637d0106cd93e6838c9c68b43325a93d jws7-tomcat-vault-1.1.11-4.Final_redhat_00003.1.el10jws.noarch.rpm SHA-256: 3c5adfb85397942620172e14d2691bcfb1dcbef5b6ec1939c7f620e6d4fdd530 jws7-tomcat-vault-javadoc-1.1.11-4.Final_redhat_00003.1.el10jws.noarch.rpm SHA-256: 55743b7c97207d485bcdd0564022e710a3b771a743849a5ccdc2ebc2705e8bfb jws7-tomcat-webapps-11.0.21-5.redhat_00004.1.el10jws.noarch.rpm SHA-256: 91dd9ccbf3c5b2272f9635955b2aef72ced850dbcc0b4f605007a47bd7d17bfa JBoss Enterprise Web Server 7 for RHEL 9 SRPM jws7-ecj-4.38.0-1.redhat_00001.1.el9jws.src.rpm SHA-256: 163eccdf9f3eae2146cf109160044893f6e33d048461050697d13b9201334249 jws7-javapackages-tools-6.0.0-1.el9jws.src.rpm SHA-256: 95a07e8dc275a2a2f0ee44725e2a97fab87767793b2b400ed2820331117f6180 jws7-jboss-logging-3.6.2-1.Final_redhat_00001.1.el9jws.src.rpm SHA-256: 7c2519f54114f7e86d7248ea9bcd46c6dc79f562575c2d0162b6a3867cf466f1 jws7-mod_cluster-2.1.0-1.Final_redhat_00001.1.el9jws.src.rpm SHA-256: 4f92865811cf6242d5cb2a7d585570ef37868e476a4149d50404f8624b9415d1 jws7-tomcat-11.0.21-5.redhat_00004.1.el9jws.src.rpm SHA-256: 5f4cb9105259fbb9f55c4a4065b21aa9188cf0e18203fc3156a0860ec28e3a39 jws7-tomcat-native-1.3.7-2.redhat_2.el9jws.src.rpm SHA-256: 4dea9410c44d233201bdfd41f8cee6ba40c3c9976b9f82212cde39f692bf0b16 jws7-tomcat-vault-1.1.11-4.Final_redhat_00003.1.el9jws.src.rpm SHA-256: 6b8d8b069af91478993f6744c338e24f2e4cb368f3a7f865f423af2a7089d158 x86_64 jws7-build-1-1.el9jws.x86_64.rpm SHA-256: 7919975d1ca4b22f580bd4d337600f240f9ea60c3931a179afa51b86270b15e1 jws7-ecj-4.38.0-1.redhat_00001.1.el9jws.noarch.rpm SHA-256: 171c4e12ba50a1d82c7bf365546ec027f5a710e3c336a149fec6c7deced70660 jws7-javapackages-filesystem-6.0.0-1.el9jws.noarch.rpm SHA-256: 20551c8a945386af8d2fb73ac9d80f189af2ab32915f5f171508f3bee5352ef4 jws7-javapackages-tools-6.0.0-1.el9jws.noarch.rpm SHA-256: 73d577f6a5
Red Hat has released an important security update for JBoss Web Server 7.0.0 addressing multiple vulnerabilities in the embedded Apache Tomcat component, including critical issues like improper authorization allowing security bypass (CVE-2026-43515, CVSS 9.1) and an HTTP/2 request header validation flaw. The affected Tomcat versions are extensive, covering major branches; for example, CVE-2026-43515 affects Apache Tomcat 7.0.0 through 7.0.109, 8.5.0 through 8.5.100, and versions 9.0.0 before 9.0.118. The fix is provided by upgrading to the new JBoss Web Server 7.0.0 release, which incorporates Tomcat versions with the necessary patches, such as Tomcat 9.0.118, 10.1.55, or 11.0.22 for the critical CVE.