Tomcat Update v9.0.117 (MINDBREEZE42440)

ID: MINDBREEZE42440 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: Critical 
Status: Affected 
First published: August 5, 2026 
CVEs: CVE-2026-34483 (GHSA-rv64-5gf8-9qq8), CVE-2026-29145 (GHSA-95jq-rwvf-vjx4),  CVE-2026-29129 (GHSA-69cc-cv78-qc8g),  CVE-2026-34500 (GHSA-24j9-x2wg-9qv6, CVE-2026-29146 (GHSA-h468-7pvh-8vr8),CVE-2026-25854 (GHSA-9m3c-qcxr-9x87), CVE-2026-34487 (GHSA-x4m4-345f-5h5g), CVE-2026-24880 (GHSA-563x-q5rq-57qp),CVE-2026-32990 (GHSA-8mc5-53m5-3qj2) 

Summary 

  • CVE-2026-29145: Apache Tomcat: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability 
  • CVE-2026-34483: Apache Tomcat: improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve 
  • CVE-2026-29129: Apache Tomcat: configured cipher preference order not preserved vulnerability 
  • GHSA-24j9-x2wg-9qv6: Apache Tomcat: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used 
  • GHSA-h468-7pvh-8vr8: Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor with default configuration. 
  • CVE-2026-25854: Apache Tomcat: Occasional URL redirection to untrusted Site (‘Open Redirect’) vulnerability in LoadBalancerDrainingValve. 
  • GHSA-x4m4-345f-5h5g: Apache Tomcat: Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component exposed the Kubernetes bearer token. 
  • GHSA-563x-q5rq-57qp: Apache Tomcat: Inconsistent Interpretation of HTTP Requests (‘HTTP Request/Response Smuggling’) vulnerability via invalid chunk extension. 
  • GHSA-8mc5-53m5-3qj2: Apache Tomcat: improper input validation vulnerability 

 

Hotfix Information 

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 26.3 Release
  • Mindbreeze InSpire SaaS 26.3 Release