Update apache tomcat to 9.0.118 (MINDBREEZE42861)

ID: MINDBREEZE42861 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: Medium 
Status: Final 
First published: August 5, 2026 
CVEs: CVE-2026-42498,CVE-2026-41293,CVE-2026-41284,CVE-2026-43515,CVE-2026-43514,CVE-2026-43513,CVE-2026-43512 

Summary 

  • CVE-2026-42498: Apache Tomcat: WebSocket authentication header exposure 
  • CVE-2026-41293: Apache Tomcat: HTTP/2 request headers not validated 
  • CVE-2026-41284: Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling 
  • CVE-2026-43515: Apache Tomcat: Security constraints not correctly applied 
  • CVE-2026-43514: Apache Tomcat: AJP secret compared in non-constant time 
  • CVE-2026-43513: Apache Tomcat: LockOutRealm treats user names as case-sensitive 
  • CVE-2026-43512: Apache Tomcat: Digest authenticator will authenticate any unknown user 

 

Hotfix Information 

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 26.4 Release
  • Mindbreeze InSpire SaaS 26.4 Release