Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:73981 - Security Advisory
Issued:
2026-10-01
Updated:
2026-10-01

RHSA-2026:73981 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Red Hat JBoss Web Server 6.2.5 release and security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Red Hat JBoss Web Server 6.2.5 is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, and Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library.

This release of Red Hat JBoss Web Server 6.2.5 serves as a replacement for Red Hat JBoss Web Server 6.2.4. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section.

Security Fix(es):

  • tomcat-catalina: Apache Tomcat: Misleading security logs due to incorrect control flow (CVE-2026-55276)
  • tomcat-coyote-ffm: Apache Tomcat: Error condition not handled when configuring CRL (CVE-2026-53434)
  • jws6-tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083)
  • tomcat: Apache Tomcat: Local information disclosure via Unix domain socket TOCTOU race condition (CVE-2026-65183)
  • tomcat: Apache Tomcat: Security constraint bypass due to improper access control (CVE-2026-65182)
  • tomcat: Apache Tomcat: Access control bypass due to off-by-one error in RewriteValve [N] flag processing (CVE-2026-65927)
  • tomcat: Apache Tomcat: Denial of Service via HTTP/2 allocation leak (CVE-2026-68763)
  • tomcat: Apache Tomcat: Unauthorized resource access via FORM authentication bypass (CVE-2026-68525)
  • tomcat: Apache Tomcat - DoS in WebSocket chat example (CVE-2026-66299)
  • tomcat: Apache Tomcat: Authenticated WebSocket session persists after HTTP session termination (CVE-2026-73180)
  • tomcat: Apache Tomcat: Improper Authorization allows bypass of declarative role constraints (CVE-2026-66422)
  • tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure (CVE-2026-68569)
  • tomcat: Apache Tomcat: Authentication bypass via limited replay attack in DIGEST authenticator (CVE-2026-65905)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Web Server 6 for RHEL 10 x86_64
  • JBoss Enterprise Web Server 6 for RHEL 9 x86_64
  • JBoss Enterprise Web Server 6 for RHEL 8 x86_64

Fixes

  • BZ - 2494668 - CVE-2026-53434 tomcat: Apache Tomcat: Error condition not handled when configuring CRLs
  • BZ - 2494675 - CVE-2026-55276 tomcat: Apache Tomcat: Misleading security logs due to incorrect control flow
  • BZ - 2499917 - CVE-2026-59083 tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve
  • BZ - 2508085 - CVE-2026-66299 tomcat: Apache Tomcat: Denial of Service via WebSocket chat example

CVEs

  • CVE-2026-53434
  • CVE-2026-55276
  • CVE-2026-59083
  • CVE-2026-65182
  • CVE-2026-65183
  • CVE-2026-65905
  • CVE-2026-65927
  • CVE-2026-66299
  • CVE-2026-66422
  • CVE-2026-68525
  • CVE-2026-68569
  • CVE-2026-68763
  • CVE-2026-73180

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://docs.redhat.com/en/documentation/red_hat_jboss_web_server/6.2/html/red_hat_jboss_web_server_6.2_service_pack_5_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Web Server 6 for RHEL 10

SRPM
jws6-tomcat-10.1.49-16.redhat_00016.1.el10jws.src.rpm SHA-256: 95cd81caa959f61ae6fcf7cf8441b450b50dc4bd966fd40f57868afeca7a0ccb
x86_64
jws6-tomcat-10.1.49-16.redhat_00016.1.el10jws.noarch.rpm SHA-256: f6b45a63f39fbab2decd7a90b0832c4b675572f35af07ad7ecbb0fb612f62031
jws6-tomcat-admin-webapps-10.1.49-16.redhat_00016.1.el10jws.noarch.rpm SHA-256: 572dc585f2e10b481bc09cc4e8442363d3d9bea11676baa0a75a45c513c9f30f
jws6-tomcat-docs-webapp-10.1.49-16.redhat_00016.1.el10jws.noarch.rpm SHA-256: 669242381e070d06328afc30b21dee1ba590f0ec96e86929c2b36d4318499948
jws6-tomcat-el-5.0-api-10.1.49-16.redhat_00016.1.el10jws.noarch.rpm SHA-256: ad7c4b4224220f6c6473e9f329f691aed94174a7b1180f3503148df3a0363ebe
jws6-tomcat-javadoc-10.1.49-16.redhat_00016.1.el10jws.noarch.rpm SHA-256: dd8cafb0794b2a5527c3c5e02d170df058f0dafdf6cd64d5e51b4f1173ee8025
jws6-tomcat-jsp-3.1-api-10.1.49-16.redhat_00016.1.el10jws.noarch.rpm SHA-256: c9cc268a02770d05527c7fb7d0c19536fd614f2b348ad144f5e8e63adf2f315a
jws6-tomcat-lib-10.1.49-16.redhat_00016.1.el10jws.noarch.rpm SHA-256: d4b15e1e4c005c3a458286e00892fa08330c023b67a6eb5aa4a79030319e4e7c
jws6-tomcat-selinux-10.1.49-16.redhat_00016.1.el10jws.noarch.rpm SHA-256: 3cb43b34d79abb0a38e67777794b76384dce3ded937b488c257dd6ce51d85b28
jws6-tomcat-servlet-6.0-api-10.1.49-16.redhat_00016.1.el10jws.noarch.rpm SHA-256: 75ede92875d9718f7bc1486cf68d57e8fd953e4fa197b50f056330741769837c
jws6-tomcat-webapps-10.1.49-16.redhat_00016.1.el10jws.noarch.rpm SHA-256: 2ee8095550e9005b59ce5f2570a0cdde833538227b93642315c8ec9da20a1848

JBoss Enterprise Web Server 6 for RHEL 9

SRPM
jws6-tomcat-10.1.49-16.redhat_00016.1.el9jws.src.rpm SHA-256: 8c97c6b40544a7cad99195864655b9c30e76efa314327eeb11b23c536400195d
x86_64
jws6-tomcat-10.1.49-16.redhat_00016.1.el9jws.noarch.rpm SHA-256: 3c867a6e33dbcf8ebd8b620b6a123b07de7977d0fec3df01c80005ff8b276644
jws6-tomcat-admin-webapps-10.1.49-16.redhat_00016.1.el9jws.noarch.rpm SHA-256: c433d9d403d0b5f25dacf675ab7defd4f8402aabd9d1b882725799d52c1cb559
jws6-tomcat-docs-webapp-10.1.49-16.redhat_00016.1.el9jws.noarch.rpm SHA-256: 0624f2d1d4b96b33a6bda647fbcd4c0d0036b33740f860fabf64e68d96a3efeb
jws6-tomcat-el-5.0-api-10.1.49-16.redhat_00016.1.el9jws.noarch.rpm SHA-256: 698fdb110d097717f1a638c8905bf95201f3dea3fe924ad355a5872e6ae0e53c
jws6-tomcat-javadoc-10.1.49-16.redhat_00016.1.el9jws.noarch.rpm SHA-256: 6f7802c475acd19bf57605688338f9f5837f6f55578a5ecbeb928f2fd22661c1
jws6-tomcat-jsp-3.1-api-10.1.49-16.redhat_00016.1.el9jws.noarch.rpm SHA-256: 360a6bce209b04d252b8d7e954a10358746a0d4a40a97803dc649f8bc5812d42
jws6-tomcat-lib-10.1.49-16.redhat_00016.1.el9jws.noarch.rpm SHA-256: 8cdf0d6cc8270ef4a571516630189a187403501889ef7177d2e2ecd277d8b2cb
jws6-tomcat-selinux-10.1.49-16.redhat_00016.1.el9jws.noarch.rpm SHA-256: 6952743f04388fc4d8701d06191764537cb674c7017e024c6c90432a4c0197c5
jws6-tomcat-servlet-6.0-api-10.1.49-16.redhat_00016.1.el9jws.noarch.rpm SHA-256: 54420533a284f380c25afa0c77163cd37ef9d1ea462dcaedf73b02a2b5dd36a7
jws6-tomcat-webapps-10.1.49-16.redhat_00016.1.el9jws.noarch.rpm SHA-256: ea0617672da6b19b37a4187e5c063bad1b246289b9d52accb0dc5a08ef06ea94

JBoss Enterprise Web Server 6 for RHEL 8

SRPM
jws6-tomcat-10.1.49-16.redhat_00016.1.el8jws.src.rpm SHA-256: 454a92e5c1b59c63dc3b03ee4679bd70fe4e24673e79f51fc226a57dc158ef7a
x86_64
jws6-tomcat-10.1.49-16.redhat_00016.1.el8jws.noarch.rpm SHA-256: 9db179fbc58c8fba30b70998be5ed704ab7791fa9111997076f2adcf3fe90943
jws6-tomcat-admin-webapps-10.1.49-16.redhat_00016.1.el8jws.noarch.rpm SHA-256: 29486c71a56962e143bdf86d226589718a40cf2d267f7a63044fd28bc1f98059
jws6-tomcat-docs-webapp-10.1.49-16.redhat_00016.1.el8jws.noarch.rpm SHA-256: dc728357fb4617489b51bdcf4138632caf20c3afffbec58280cd9a35b27b3d61
jws6-tomcat-el-5.0-api-10.1.49-16.redhat_00016.1.el8jws.noarch.rpm SHA-256: 0ae8f9dc5b57f1a54703680efc00d2d70eee19fcebe55d590714c2e8faf2e924
jws6-tomcat-javadoc-10.1.49-16.redhat_00016.1.el8jws.noarch.rpm SHA-256: dc65c73a9cce1f2e0ee60b2b191d67b517681442d8207e8546c1fbf8f88c9f42
jws6-tomcat-jsp-3.1-api-10.1.49-16.redhat_00016.1.el8jws.noarch.rpm SHA-256: bf7f24721835f08854286c45c23da3e698063a75509d164799fef3bce60d3009
jws6-tomcat-lib-10.1.49-16.redhat_00016.1.el8jws.noarch.rpm SHA-256: 03ac4ecf14492bb73f3d5412490848e746cc6e3efedb88cb7b9c16ae0ca38141
jws6-tomcat-selinux-10.1.49-16.redhat_00016.1.el8jws.noarch.rpm SHA-256: 35f6af3b5281feed1bb4217dd947edf8c41a9bef563c2e35efddec67d460f7f6
jws6-tomcat-servlet-6.0-api-10.1.49-16.redhat_00016.1.el8jws.noarch.rpm SHA-256: 452d93479e4b918a717753014b3ba440ed4676b3a46f20d16c0baed58b2a88ba
jws6-tomcat-webapps-10.1.49-16.redhat_00016.1.el8jws.noarch.rpm SHA-256: 7993b171dc222ba21efbfcfab2f372a4225a76c41ba3ed452ff2538fd33776ef

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility