Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5611 - Security Advisory
Issued:
2026-03-25
Updated:
2026-03-25

RHSA-2026:5611 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Red Hat JBoss Web Server 6.2.1 release and security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Red Hat JBoss Web Server 6.2.1 is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, and Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library.

This release of Red Hat JBoss Web Server 6.2.1 serves as a replacement for Red Hat JBoss Web Server 6.2.0. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section.

Security Fix(es):

  • tomcat: Apache Tomcat: Certificate revocation bypass due to improper OCSP response validation (CVE-2026-24734)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Web Server 6 for RHEL 10 x86_64
  • JBoss Enterprise Web Server 6 for RHEL 9 x86_64
  • JBoss Enterprise Web Server 6 for RHEL 8 x86_64

Fixes

  • BZ - 2440426 - CVE-2026-24734 tomcat: Apache Tomcat: Certificate revocation bypass due to improper OCSP response validation

CVEs

  • CVE-2026-24734

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://docs.redhat.com/en/documentation/red_hat_jboss_web_server/6.2/html/red_hat_jboss_web_server_6.2_service_pack_1_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Web Server 6 for RHEL 10

SRPM
jws6-tomcat-10.1.49-9.redhat_00007.1.el10jws.src.rpm SHA-256: b50ec4d042d4946e421f6e87f4e38df45e5c4d22fc67de7535e458df6be4592a
jws6-tomcat-native-1.3.6-1.redhat_1.el10jws.src.rpm SHA-256: cdbf275a14f42be62f5708545b69bc3bbc0fa1ef71200041b289f510818f9e6a
x86_64
jws6-tomcat-10.1.49-9.redhat_00007.1.el10jws.noarch.rpm SHA-256: 2a81ec83303278e91686bf32ebcd459c43b5cf8d15e24daa4a0fd8bdf268aa93
jws6-tomcat-admin-webapps-10.1.49-9.redhat_00007.1.el10jws.noarch.rpm SHA-256: 79b2cb66018ae5b38eb98e72dd10204b5dc4953208e92de99201bd17028e4a93
jws6-tomcat-docs-webapp-10.1.49-9.redhat_00007.1.el10jws.noarch.rpm SHA-256: 716713742e01987ee4e22beaebc68f9cafe01d3f09923709d484efda79550cb2
jws6-tomcat-el-5.0-api-10.1.49-9.redhat_00007.1.el10jws.noarch.rpm SHA-256: 7fda8878613d9162f37a81506e7848c7f7efb18e549bef1c4efff6e9086a34ec
jws6-tomcat-javadoc-10.1.49-9.redhat_00007.1.el10jws.noarch.rpm SHA-256: 194df924523ef60bb415a12de2d9850607e85189af590f9b982962891f2e03c4
jws6-tomcat-jsp-3.1-api-10.1.49-9.redhat_00007.1.el10jws.noarch.rpm SHA-256: cff6490ae40a199a45847acdf48891f1aef3e21ce8256595d8241a87220f16d7
jws6-tomcat-lib-10.1.49-9.redhat_00007.1.el10jws.noarch.rpm SHA-256: 8bf9c042e7a65dc21bcab63180b2beea8da289737385decde2acfc25d55a9e89
jws6-tomcat-native-1.3.6-1.redhat_1.el10jws.x86_64.rpm SHA-256: 8f846f3d48e96faf6fa00159c3d12f76a951775b3c13ac28c1f909292efac83f
jws6-tomcat-native-debuginfo-1.3.6-1.redhat_1.el10jws.x86_64.rpm SHA-256: 3cddafa434f14035f56d1ca1f3b60c7ead0646c1513e330b0815c0ead25d4217
jws6-tomcat-selinux-10.1.49-9.redhat_00007.1.el10jws.noarch.rpm SHA-256: 2630363ff416a57f9a8ce3e98a99ad97ab8407a2b00cfab65cb55d40fc74d9bc
jws6-tomcat-servlet-6.0-api-10.1.49-9.redhat_00007.1.el10jws.noarch.rpm SHA-256: aa9924ff15f91dd0d86a15bfe684639faaeabe39613278fa3b1401d5461313f1
jws6-tomcat-webapps-10.1.49-9.redhat_00007.1.el10jws.noarch.rpm SHA-256: f866356b3988ac0013265e22bff9e9e35c2c5036d0e143eb1fcab3ed581df6a1

JBoss Enterprise Web Server 6 for RHEL 9

SRPM
jws6-tomcat-10.1.49-9.redhat_00007.1.el9jws.src.rpm SHA-256: 0de94260269337275b15932a3c098d607ef214da38ed8727f6b7f2cf90e1ede1
jws6-tomcat-native-1.3.6-1.redhat_1.el9jws.src.rpm SHA-256: 51d1805e4126b980250717c45a3b9c3e0cc25a2b482c0f372eba90a7f390e2f9
x86_64
jws6-tomcat-10.1.49-9.redhat_00007.1.el9jws.noarch.rpm SHA-256: 53833f589c270a3762d6e227971045d91881f4f2144288e0dd97685da6ea30a7
jws6-tomcat-admin-webapps-10.1.49-9.redhat_00007.1.el9jws.noarch.rpm SHA-256: ccdef5177f4a5242658688a708d242845c1d542f2b93e193ffec01d302068dc3
jws6-tomcat-docs-webapp-10.1.49-9.redhat_00007.1.el9jws.noarch.rpm SHA-256: aae0543d55fcfc63b3f1f14427a4ca9a4b4fa29dc287dbb41a5f7eb72a76d08a
jws6-tomcat-el-5.0-api-10.1.49-9.redhat_00007.1.el9jws.noarch.rpm SHA-256: 2591c838be8333aa2f1eb2319e0efb815f2a6d69366360a5730273acabc39f45
jws6-tomcat-javadoc-10.1.49-9.redhat_00007.1.el9jws.noarch.rpm SHA-256: ef593552f83c068f9a7c570829b495fcb916cfc72a3622f979947b7e4a277a2b
jws6-tomcat-jsp-3.1-api-10.1.49-9.redhat_00007.1.el9jws.noarch.rpm SHA-256: f5b9cafe584e1237dfe8a753f7adb1e7ccc9bd0afe10ca1b1abd4561707d3158
jws6-tomcat-lib-10.1.49-9.redhat_00007.1.el9jws.noarch.rpm SHA-256: 8f58e9ae12fcefa714393fc9bba2555297afaf80e9ef617d2ee9bc95681c8d67
jws6-tomcat-native-1.3.6-1.redhat_1.el9jws.x86_64.rpm SHA-256: f36cec0ebf40822bd0697ce0fe695060f797890c1049548abd753821b1755b05
jws6-tomcat-native-debuginfo-1.3.6-1.redhat_1.el9jws.x86_64.rpm SHA-256: 01251c76ddc9e1bbbc350ba55c7f7d8b855bb878bb7f85215130ac1cd9a87bdd
jws6-tomcat-selinux-10.1.49-9.redhat_00007.1.el9jws.noarch.rpm SHA-256: 47b4eda98bfcfea8feff3f978c6d3102d6522a03133600285513dcb8f9a29e13
jws6-tomcat-servlet-6.0-api-10.1.49-9.redhat_00007.1.el9jws.noarch.rpm SHA-256: df085a48d5ece13e12bb394726088b7f589ee4685421a86ed9cc92ace170b1d3
jws6-tomcat-webapps-10.1.49-9.redhat_00007.1.el9jws.noarch.rpm SHA-256: d44d4a1b72db1abf5a05e893ad8fa35a017b78ac33669b15e0a50955a0dd29de

JBoss Enterprise Web Server 6 for RHEL 8

SRPM
jws6-tomcat-10.1.49-9.redhat_00007.1.el8jws.src.rpm SHA-256: 5726e57ef3702142cd52f0f71300e7230e230e489708957d1aac880da1b76271
jws6-tomcat-native-1.3.6-1.redhat_1.el8jws.src.rpm SHA-256: 241af28b099a9da547634740b9cad504cfd9dee99d92b0de728b507ad66b17d7
x86_64
jws6-tomcat-10.1.49-9.redhat_00007.1.el8jws.noarch.rpm SHA-256: 24d3702efdda616ac19ec9d9e74ea48f72ccb917de96995687fedea9713a5cfe
jws6-tomcat-admin-webapps-10.1.49-9.redhat_00007.1.el8jws.noarch.rpm SHA-256: 2de9a2962572160b0ae106797bbd95aee8794bf11e36af4a40beed00bfe9d84e
jws6-tomcat-docs-webapp-10.1.49-9.redhat_00007.1.el8jws.noarch.rpm SHA-256: 0c0ff85576d558579df5ed5d3efc5cd26ceaf7a0a536d57d560516e35acb413e
jws6-tomcat-el-5.0-api-10.1.49-9.redhat_00007.1.el8jws.noarch.rpm SHA-256: eca32d1eb93af56f46309e5e93df59d46b61b6225b8abfd018ba540110604816
jws6-tomcat-javadoc-10.1.49-9.redhat_00007.1.el8jws.noarch.rpm SHA-256: 5e1aac6b30b062b462a22fda80745b51bab09250ec95d953bd450766dc096190
jws6-tomcat-jsp-3.1-api-10.1.49-9.redhat_00007.1.el8jws.noarch.rpm SHA-256: a9673d035a62cd6865a5a213a6ee8b3dd7eeb923a8270fe233e980bb6c49bce8
jws6-tomcat-lib-10.1.49-9.redhat_00007.1.el8jws.noarch.rpm SHA-256: 14e31f0aac2b6eef231c0cd139ef5d2c4444184f13fb3d2b92e12f1d7173220a
jws6-tomcat-native-1.3.6-1.redhat_1.el8jws.x86_64.rpm SHA-256: 133b592192ca2a09b5e747e8f287d4f1af8ba539af35936f77713930ef523355
jws6-tomcat-native-debuginfo-1.3.6-1.redhat_1.el8jws.x86_64.rpm SHA-256: 250414195fb10d147d97a2df81712b2dea061e81f8f2241f6a6ba2fd40042b63
jws6-tomcat-selinux-10.1.49-9.redhat_00007.1.el8jws.noarch.rpm SHA-256: 567c5d9bcc3de67ca97a1160afa261c9e16ac3085711de8319022530f56c9a9d
jws6-tomcat-servlet-6.0-api-10.1.49-9.redhat_00007.1.el8jws.noarch.rpm SHA-256: f9cf5fea75096b2c6d82ec82b8a3867f874dc44266192b3462328fde2ff09fa4
jws6-tomcat-webapps-10.1.49-9.redhat_00007.1.el8jws.noarch.rpm SHA-256: 3da8b1ebb8f3821c50ba3be87ca9a95c2fe90b42589af313b81a73291a80c088

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility