live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
releaseSECURITY

Tomcat 10.1.59 closes nine exposure paths in Red Hat Hardened Images

The update reaches internet-facing HTTP/2 and authentication paths, but several fixes matter only when specific Tomcat features are enabled.

Before-and-after Tomcat image update with security-sensitive paths
Side by side: what changed
By The News Desk· Sep 4, 2026the quick take — two AI hosts go live when you do

Red Hat has updated the Tomcat 10 packages in Red Hat Hardened Images to 10.1.59-0.1.hum1, carrying fixes for nine CVEs. The Red Hat advisory names every Tomcat RPM in the image set, from the core package and libraries to the admin, documentation and user-instance web applications.

The practical risk is configuration-dependent. Image consumers should map the fixes to the Tomcat features their workloads actually expose rather than treating the advisory as nine identical defects.

Where the exposure sits

Two fixes are most relevant to public HTTP traffic. Apache’s Tomcat 10 security page rates CVE-2026-68763 Important: repeatedly reset HTTP/2 streams could leak backlog allocations until the process failed. CVE-2026-65637 completes strict SNI validation for HTTP/2 requests without an authority value.

Four more flaws sit in authorization policy. CVE-2026-65182 could bypass constraints when a longer path appeared before a stricter shorter sub-path. CVE-2026-65927 made RewriteValve’s [N] flag restart at the second rule, potentially skipping an access-control rule. CVE-2026-68525 affected method-specific constraints after FORM authentication, while CVE-2026-66422 could turn servlet role references into unintended Realm aliases.

Authentication and session handling account for two further cases. CVE-2026-65905 permitted a limited one-time replay under DIGEST authentication. CVE-2026-73180 allowed an authenticated WebSocket to survive the end of its associated HTTP session after the session ID changed. CVE-2026-65183 is narrower: a race while creating a Unix domain socket could expose it to an unauthorized local user.

Apache says all nine affected Tomcat 10.1 releases through 10.1.57; 10.1.59 is the first released build carrying the fixes because the 10.1.58 release vote did not pass.

A rollout checklist for image consumers

This desk recommends a staged rebuild rather than an in-place assumption:

  1. Inventory deployments derived from the Tomcat 10 Hardened Image and identify which use HTTP/2, strict SNI, RewriteValve, FORM or DIGEST authentication, declarative role constraints, WebSockets or Unix domain sockets.
  2. Rebuild application images from the refreshed Red Hat source and confirm the installed RPM reports 10.1.59-0.1.hum1; pin the resulting image digest in deployment manifests.
  3. In staging, exercise reset-heavy HTTP/2 traffic and repeat authorization tests for shorter paths, method constraints, rewritten routes and role aliases. Verify that WebSockets close when the parent HTTP session ends.
  4. Roll out with normal health and error-rate gates, then confirm every running replica uses the new digest. Preserve the previous digest for rollback, but do not leave old replicas serving traffic after validation.

The update is broad, but the highest-priority rebuilds are internet-facing HTTP/2 services and applications that depend on Tomcat’s own rewrite or declarative access controls.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.