RHSA-2026%3A12195
A certificate validation flaw has been found in Apache Tomcat. omcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web application.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Web Server 6.2.2 |
Timeline
- Apr 30, 2026 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- Jul 23, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:12195 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_web_server/6.2/html/red_hat_jboss_web_server_6.2_service_pack_2_release_notes/index advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2440430 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2440437 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2451094 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2457025 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_12195.json advisory
- https://access.redhat.com/security/cve/CVE-2025-66614 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-66614 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-66614 advisory
- https://lists.apache.org/thread/vw6lxtlh2qbqwpb61wd3sv1flm2nttw7 advisory
- https://access.redhat.com/security/cve/CVE-2026-24733 advisory
- https://www.cve.org/CVERecord?id=CVE-2026-24733 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-24733 advisory
- https://lists.apache.org/thread/6xk3t65qpn1myp618krtfotbjn1qt90f advisory
- https://access.redhat.com/security/cve/CVE-2026-31790 advisory
- https://www.cve.org/CVERecord?id=CVE-2026-31790 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-31790 advisory
- https://openssl-library.org/news/secadv/20260407.txt advisory
…and 4 more