Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:49951 - Security Advisory
Issued:
2026-08-05
Updated:
2026-08-05

RHSA-2026:49951 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: Red Hat JBoss Web Server 7.0.1 release and security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Red Hat JBoss Web Server 7.0.1 is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, and Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library.

This release of Red Hat JBoss Web Server 7.0.1 serves as a replacement for Red Hat JBoss Web Server 7.0.0. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section.

Security Fix(es):

  • tomcat-catalina: Apache Tomcat: Misleading security logs due to incorrect control flow (CVE-2026-55276)
  • tomcat-coyote-ffm: Apache Tomcat: Error condition not handled when configuring CRLs (CVE-2026-53434)
  • tomcat-catalina: Apache Tomcat: Incorrect control flow in rewrite valve allows unexpected rule processing (CVE-2026-53404)
  • tomcat: Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass (CVE-2026-59083)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Web Server 7 for RHEL 10 x86_64
  • JBoss Enterprise Web Server 7 for RHEL 9 x86_64
  • JBoss Enterprise Web Server 7 for RHEL 8 x86_64

Fixes

  • BZ - 2494668 - CVE-2026-53434 tomcat: Apache Tomcat: Error condition not handled when configuring CRLs
  • BZ - 2494675 - CVE-2026-55276 tomcat: Apache Tomcat: Misleading security logs due to incorrect control flow
  • BZ - 2494681 - CVE-2026-53404 Apache Tomcat: Apache Tomcat: Incorrect control flow in rewrite valve allows unexpected rule processing
  • BZ - 2499917 - CVE-2026-59083 tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve

CVEs

  • CVE-2026-53404
  • CVE-2026-53434
  • CVE-2026-55276
  • CVE-2026-59083

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://docs.redhat.com/en/documentation/red_hat_jboss_web_server/7.0/html/red_hat_jboss_web_server_7.0_service_pack_1_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Web Server 7 for RHEL 10

SRPM
jws7-tomcat-11.0.21-6.redhat_00005.1.el10jws.src.rpm SHA-256: 667036f3d678f9310abec62c749e92a799c02268e3a217a48ab9e20b7eee5357
x86_64
jws7-tomcat-11.0.21-6.redhat_00005.1.el10jws.noarch.rpm SHA-256: 5073bcd7c4956c7695001a7f41f1b5c552303b51d52aabf577577f30983adb07
jws7-tomcat-admin-webapps-11.0.21-6.redhat_00005.1.el10jws.noarch.rpm SHA-256: 48d9c03c12786fe35aa5494eb3e4dd499e6d43fe2653796c446ff0f806a950b1
jws7-tomcat-docs-webapp-11.0.21-6.redhat_00005.1.el10jws.noarch.rpm SHA-256: ebd78b757ab5b14525ca516755e1a067550f34d921b8a9c0a3130a4a59b72e5c
jws7-tomcat-el-5.0-api-11.0.21-6.redhat_00005.1.el10jws.noarch.rpm SHA-256: cf5cc946736013985a04d44f05f31b3c220cb18d6ffad1a7ba5341b480d73bbc
jws7-tomcat-javadoc-11.0.21-6.redhat_00005.1.el10jws.noarch.rpm SHA-256: df9bca27557eb339a12bd9d47fb5def59f8ce5d336a9a8896654f3c55f1e46a2
jws7-tomcat-jsp-3.1-api-11.0.21-6.redhat_00005.1.el10jws.noarch.rpm SHA-256: f2605e3e9943bc27bee4169b9ef189a80c6838f9b45e21a03b009ef7b91546db
jws7-tomcat-lib-11.0.21-6.redhat_00005.1.el10jws.noarch.rpm SHA-256: 2207f0595a51dacbdcb0e07b3dac55d5b0976b8e3dba78351334061fd1f721cb
jws7-tomcat-selinux-11.0.21-6.redhat_00005.1.el10jws.noarch.rpm SHA-256: adbe46246f980823e9b2c528162a87f564d7f36bd7df0ad7b3fd36c1be534e1c
jws7-tomcat-servlet-6.0-api-11.0.21-6.redhat_00005.1.el10jws.noarch.rpm SHA-256: dc5ef2c56fe565750783c595dab1cf038c94164053a54318d90bde732896dc65
jws7-tomcat-webapps-11.0.21-6.redhat_00005.1.el10jws.noarch.rpm SHA-256: de88600f4f9128e182fd9a56129870f4ad54cf82954d7f38f9d4dc4c477bbf96

JBoss Enterprise Web Server 7 for RHEL 9

SRPM
jws7-tomcat-11.0.21-6.redhat_00005.1.el9jws.src.rpm SHA-256: faba485acfa0e14062c8860f30f0751939cfa03b9a6e148feb0f41d1a4ba153a
x86_64
jws7-tomcat-11.0.21-6.redhat_00005.1.el9jws.noarch.rpm SHA-256: 651e4b8fd7823630fbee861effbf23a9b363d266d4d3909bbe52243f31cb47c4
jws7-tomcat-admin-webapps-11.0.21-6.redhat_00005.1.el9jws.noarch.rpm SHA-256: f4716d8422717b47c48a7fc6576d99b29925a518b23d0b2e0af16931bca6bf6f
jws7-tomcat-docs-webapp-11.0.21-6.redhat_00005.1.el9jws.noarch.rpm SHA-256: 6f9a6683c9507aadbe942ab8edd69eb43f5cf2147ef2a8de176df1cb04b0f3ef
jws7-tomcat-el-5.0-api-11.0.21-6.redhat_00005.1.el9jws.noarch.rpm SHA-256: 59670c3fd9a12e790da580d0ce01cc429f23f5f51bdbc1e7837215d6efdba63c
jws7-tomcat-javadoc-11.0.21-6.redhat_00005.1.el9jws.noarch.rpm SHA-256: d69e31e3f66f1e7c996e33fa3a5411a6e08e23228ab1d93b0d50248e7ec19106
jws7-tomcat-jsp-3.1-api-11.0.21-6.redhat_00005.1.el9jws.noarch.rpm SHA-256: 421fe77b16b5beae67bc4f5cd06d09364e4991f5fb3445b8055f31612dd3aac7
jws7-tomcat-lib-11.0.21-6.redhat_00005.1.el9jws.noarch.rpm SHA-256: ac975ec2d0bcb6e58141ebe5553700fcc60a8563197c845e91d0e04ff8dd6f6e
jws7-tomcat-selinux-11.0.21-6.redhat_00005.1.el9jws.noarch.rpm SHA-256: f9c70f1bbf0b5a707e5cba00c0fce6c3ff87ba8c18dd436bbe63688df5b3760a
jws7-tomcat-servlet-6.0-api-11.0.21-6.redhat_00005.1.el9jws.noarch.rpm SHA-256: 702042f035a65bd75e03f863a0b7a63e06ed7d3bdccf6e15351ea5d53af6b04e
jws7-tomcat-webapps-11.0.21-6.redhat_00005.1.el9jws.noarch.rpm SHA-256: 5054a622a832111ce5da6d631a1d0b67d3b5eb8d10c6674fa3cd3a3bd05313f2

JBoss Enterprise Web Server 7 for RHEL 8

SRPM
jws7-tomcat-11.0.21-6.redhat_00005.1.el8jws.src.rpm SHA-256: e9b0b5d058828a697c8002826248a51e858374bc34545e8b37fac6818c552a94
x86_64
jws7-tomcat-11.0.21-6.redhat_00005.1.el8jws.noarch.rpm SHA-256: 0c94bb9c5121799602d66c4f91b2d37e34de2509b106718f2d14b0ddd1889d34
jws7-tomcat-admin-webapps-11.0.21-6.redhat_00005.1.el8jws.noarch.rpm SHA-256: 265bf4b92ae41bd8981463167b97022de5689bf1e849372aecc1834649d47c35
jws7-tomcat-docs-webapp-11.0.21-6.redhat_00005.1.el8jws.noarch.rpm SHA-256: c5a2fb83cc86057704d7985b96b4a4b31416a4b6a247083ce26087c2011ff299
jws7-tomcat-el-5.0-api-11.0.21-6.redhat_00005.1.el8jws.noarch.rpm SHA-256: 33398effe594ab8ed52fcb12959be2e23f235ec7aec6f81b57796bb243d498a4
jws7-tomcat-javadoc-11.0.21-6.redhat_00005.1.el8jws.noarch.rpm SHA-256: aa562dfa0ad34d5262026e85f712e86d9bb93baa168a14fb7bf96168566473f7
jws7-tomcat-jsp-3.1-api-11.0.21-6.redhat_00005.1.el8jws.noarch.rpm SHA-256: 0f61ef5cae8d407d552e5402a5b742d9ff76b9d9c10d9318fc1ae735f6ad1202
jws7-tomcat-lib-11.0.21-6.redhat_00005.1.el8jws.noarch.rpm SHA-256: dd80f2c5ed93ee68be19e7298957828f9c0185201e0070f2839c8c9bd0ef87b5
jws7-tomcat-selinux-11.0.21-6.redhat_00005.1.el8jws.noarch.rpm SHA-256: dd39307978b8fceda2dce3ab0efdc0015215bfb39c350e0c64703a8bc253cbfe
jws7-tomcat-servlet-6.0-api-11.0.21-6.redhat_00005.1.el8jws.noarch.rpm SHA-256: 4fdc672e1e7f2140a7a0bc3b1ebe74fddb2c418ff9daa7216b7a683e6f3416a5
jws7-tomcat-webapps-11.0.21-6.redhat_00005.1.el8jws.noarch.rpm SHA-256: e44605d4d5ccc4a94e9ae39adbd5e55d9c4d79c00cf116b6e5965156b0e4d5e7

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility