tomcat-9.0.117-1.el9_8

エラータID: AXSA:2026-1349:05

Release date: 
Monday, July 27, 2026 - 19:40
Subject: 
tomcat-9.0.117-1.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.

Security Fix(es):

* tomcat: Apache Tomcat: Certificate revocation bypass due to improper OCSP response validation (CVE-2026-24734)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-24734
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native:  from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. tomcat-9.0.117-1.el9_8.src.rpm
    MD5: 46abd2d493bc4ddef38064f1dc91251e
    SHA-256: 78d54c1de75123ca5b4bddc477090187b7ece2b34cd6418875308302ca929fe9
    Size: 7.16 MB

Asianux Server 9 for x86_64
  1. tomcat-9.0.117-1.el9_8.noarch.rpm
    MD5: 9f1d01aecdacaf299193aa6484b95695
    SHA-256: 870d999e906cff2d1fc734f3e135191a32a50284836ce9a7330aace4a9806957
    Size: 99.75 kB
  2. tomcat-admin-webapps-9.0.117-1.el9_8.noarch.rpm
    MD5: 742d921814d1f950b1398bdd102f10c4
    SHA-256: 65f1bdfa16cb528827df9159bb0bd5f92c9acbd71a53be7cf3d3625e67f1157b
    Size: 85.02 kB
  3. tomcat-docs-webapp-9.0.117-1.el9_8.noarch.rpm
    MD5: 7e68f51b3a001ebf451515aaf3d8faf0
    SHA-256: fe92af4a57a9f42fe2cdbc4103ce06e839e0a01262150fba775795a318300e49
    Size: 1.52 MB
  4. tomcat-el-3.0-api-9.0.117-1.el9_8.noarch.rpm
    MD5: a1573268c936bec1c9b5210612fc403d
    SHA-256: 21b613f94e15f71ac064caccbfab680e4086c9cf884db67d5551f13316ab22f5
    Size: 105.86 kB
  5. tomcat-jsp-2.3-api-9.0.117-1.el9_8.noarch.rpm
    MD5: ea697df99382a0a04755b6eedd404044
    SHA-256: 121c6240b83ac543344412f49229a50875e303299f4624a379b9c583b4fb524d
    Size: 73.75 kB
  6. tomcat-lib-9.0.117-1.el9_8.noarch.rpm
    MD5: f5375b2f186504e4987e803262204bf9
    SHA-256: 2ee0654589713d3671f483e02ef16ea422da9622be07adc170c20fdc69991f84
    Size: 6.44 MB
  7. tomcat-servlet-4.0-api-9.0.117-1.el9_8.noarch.rpm
    MD5: 4f439b67a05093a70d140fc8e6f48804
    SHA-256: 9c5e3e84aa6fb8d4db85085b7a697ffa05a621c924aceda0b65bfdb0e8c076ac
    Size: 285.37 kB
  8. tomcat-webapps-9.0.117-1.el9_8.noarch.rpm
    MD5: 6d6e35a2d113810c5610c8572dd38ddd
    SHA-256: f779a761a307bce9b9f701452be9b80f3cebe30b3c809f2dd236ce162cbf599b
    Size: 76.78 kB