Update apache tomcat to 9.0.118 (MINDBREEZE42861)
ID: MINDBREEZE42861
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS
Severity: Medium
Status: Final
First published: August 5, 2026
CVEs: CVE-2026-42498,CVE-2026-41293,CVE-2026-41284,CVE-2026-43515,CVE-2026-43514,CVE-2026-43513,CVE-2026-43512
Summary
- CVE-2026-42498: Apache Tomcat: WebSocket authentication header exposure
- CVE-2026-41293: Apache Tomcat: HTTP/2 request headers not validated
- CVE-2026-41284: Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
- CVE-2026-43515: Apache Tomcat: Security constraints not correctly applied
- CVE-2026-43514: Apache Tomcat: AJP secret compared in non-constant time
- CVE-2026-43513: Apache Tomcat: LockOutRealm treats user names as case-sensitive
- CVE-2026-43512: Apache Tomcat: Digest authenticator will authenticate any unknown user
Hotfix Information
Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS:
- Mindbreeze InSpire 26.4 Release
- Mindbreeze InSpire SaaS 26.4 Release