Tomcat Update v9.0.117 (MINDBREEZE42440)
ID: MINDBREEZE42440
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS
Severity: Critical
Status: Affected
First published: August 5, 2026
CVEs: CVE-2026-34483 (GHSA-rv64-5gf8-9qq8), CVE-2026-29145 (GHSA-95jq-rwvf-vjx4), CVE-2026-29129 (GHSA-69cc-cv78-qc8g), CVE-2026-34500 (GHSA-24j9-x2wg-9qv6, CVE-2026-29146 (GHSA-h468-7pvh-8vr8),CVE-2026-25854 (GHSA-9m3c-qcxr-9x87), CVE-2026-34487 (GHSA-x4m4-345f-5h5g), CVE-2026-24880 (GHSA-563x-q5rq-57qp),CVE-2026-32990 (GHSA-8mc5-53m5-3qj2)
Summary
- CVE-2026-29145: Apache Tomcat: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability
- CVE-2026-34483: Apache Tomcat: improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
- CVE-2026-29129: Apache Tomcat: configured cipher preference order not preserved vulnerability
- GHSA-24j9-x2wg-9qv6: Apache Tomcat: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used
- GHSA-h468-7pvh-8vr8: Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor with default configuration.
- CVE-2026-25854: Apache Tomcat: Occasional URL redirection to untrusted Site (‘Open Redirect’) vulnerability in LoadBalancerDrainingValve.
- GHSA-x4m4-345f-5h5g: Apache Tomcat: Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component exposed the Kubernetes bearer token.
- GHSA-563x-q5rq-57qp: Apache Tomcat: Inconsistent Interpretation of HTTP Requests (‘HTTP Request/Response Smuggling’) vulnerability via invalid chunk extension.
- GHSA-8mc5-53m5-3qj2: Apache Tomcat: improper input validation vulnerability
Hotfix Information
Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS:
- Mindbreeze InSpire 26.3 Release
- Mindbreeze InSpire SaaS 26.3 Release