Fedora Account System
Red Hat Associate
Red Hat Customer
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
This issue has been addressed in the following products: Red Hat JBoss Web Server 7.0.0 Via RHSA-2026:39189 https://access.redhat.com/errata/RHSA-2026:39189
This issue has been addressed in the following products: Red Hat JBoss Web Server 7.0 on RHEL 10 Red Hat JBoss Web Server 7.0 on RHEL 8 Red Hat JBoss Web Server 7.0 on RHEL 9 Via RHSA-2026:39188 https://access.redhat.com/errata/RHSA-2026:39188
This issue has been addressed in the following products: Red Hat JBoss Web Server 6.2.4 Via RHSA-2026:43402 https://access.redhat.com/errata/RHSA-2026:43402
This issue has been addressed in the following products: Red Hat JBoss Web Server 6.2 on RHEL 10 Red Hat JBoss Web Server 6.2 on RHEL 8 Red Hat JBoss Web Server 6.2 on RHEL 9 Via RHSA-2026:43401 https://access.redhat.com/errata/RHSA-2026:43401
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:67164 https://access.redhat.com/errata/RHSA-2026:67164
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:67163 https://access.redhat.com/errata/RHSA-2026:67163
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:68659 https://access.redhat.com/errata/RHSA-2026:68659
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:68678 https://access.redhat.com/errata/RHSA-2026:68678
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:68679 https://access.redhat.com/errata/RHSA-2026:68679
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:68680 https://access.redhat.com/errata/RHSA-2026:68680
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:68660 https://access.redhat.com/errata/RHSA-2026:68660
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:68677 https://access.redhat.com/errata/RHSA-2026:68677
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:68651 https://access.redhat.com/errata/RHSA-2026:68651
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:69259 https://access.redhat.com/errata/RHSA-2026:69259