Multiple Apache Tomcat vulnerabilities
39018
22 September 2026
22 September 2026
CLOSED
MEDIUM
Varies
CVE-2026-34500, CVE-2026-34487, CVE-2026-34486, CVE-2026-34483, CVE-2026-32990, CVE-2026-29146, CVE-2026-29145, CVE-2026-29129, CVE-2026-25854, CVE-2026-24880
|
Brocade Security Advisory ID |
BSA-2026-3719 |
|
Component |
Apache Tomcat |
|
|
|
Summary
- Moderate: Apache Tomcat: Fix for CVE-2025-66614 is incomplete CVE-2026-32990
The validation of SNI name and host name did not take account of possible differences in case allowing the strict SNI checks to be bypassed.
- Important: Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default CVE-2026-29146
The EncryptInterceptor used CBC by default which is vulnerable to a padding Oracle attack.
- Moderate: Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled CVE-2026-29145
CLIENT_CERT authentication did not fail OCSP checks as expected for some scenarios when soft fail was disabled.
- Low: Apache Tomcat: TLS cipher order is not preserved CVE-2026-29129
The additional of the ability to configure TLS 1.3 cipher suites did not preserve the order of the configured cipher suites and ciphers.
- Low: Apache Tomcat: Occasionally open redirect CVE-2026-25854
When a Tomcat node in a cluster with the LoadBalancerDrainingValve was in the disabled (draining) state, a specially crafted URL could be used to trigger a redirect to a URI of the attackers choice.
- Low: Apache Tomcat: Request smuggling via invalid chunk extension CVE-2026-24880
Tomcat did not validate that contents of HTTP/1.1 chunk extensions. This enabled a request smuggling attack if a reverse proxy in front of Tomcat allowed CRLF sequences in an otherwise valid chunk extension. - Moderate: Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled CVE-2026-34500
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used.
- Low: Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token CVE-2026-34487
The cloud membership for clustering component exposed the Kubernetes bearer token in log messages.
- Important: Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor CVE-2026-34486
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
- Low: Apache Tomcat: Incomplete escaping of JSON access logs CVE-2026-34483
Incomplete escaping when non-default values were used for the Connector attributes relaxedPathChars and/or relaxedQueryChars allowed the injection of arbitrary JSON into the JSON access log.
Products Affected
- No Brocade products are affected
Products Not Affected
- Brocade Fabric OS
[VEX Justification: Component_not_present] - Brocade SANnav
[VEX Justification: Vulnerable_code_not_in_execute_path] - Brocade ASCG
[VEX Justification: Component_not_present]
Solution
- While not exploitable, security update provided in Brocade SANnav 3.0.0a and 3.0.1a
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
September 22, 2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.