{
  "schema_version": "1.7.0",
  "id": "RHSA-2026:68257",
  "related": [],
  "upstream": [
    "CVE-2026-41284",
    "CVE-2026-68569",
    "CVE-2026-73581",
    "CVE-2026-75973",
    "CVE-2026-76183",
    "CVE-2026-77791",
    "CVE-2026-78383",
    "CVE-2026-78437",
    "CVE-2026-79677",
    "CVE-2026-86350",
    "CVE-2026-87022"
  ],
  "published": "2026-09-22T10:19:07Z",
  "modified": "2026-09-29T10:17:10Z",
  "summary": "Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update",
  "severity": [
    {
      "type": "CVSS_V3",
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
    }
  ],
  "affected": [
    {
      "package": {
        "name": "tomcat10",
        "ecosystem": "Red Hat:hummingbird:1",
        "purl": "pkg:rpm/redhat/tomcat10"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:10.1.60-0.1.hum1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "tomcat10-admin-webapps",
        "ecosystem": "Red Hat:hummingbird:1",
        "purl": "pkg:rpm/redhat/tomcat10-admin-webapps"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:10.1.60-0.1.hum1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "tomcat10-common",
        "ecosystem": "Red Hat:hummingbird:1",
        "purl": "pkg:rpm/redhat/tomcat10-common"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:10.1.60-0.1.hum1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "tomcat10-docs-webapp",
        "ecosystem": "Red Hat:hummingbird:1",
        "purl": "pkg:rpm/redhat/tomcat10-docs-webapp"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:10.1.60-0.1.hum1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "tomcat10-el-5.0-api",
        "ecosystem": "Red Hat:hummingbird:1",
        "purl": "pkg:rpm/redhat/tomcat10-el-5.0-api"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:10.1.60-0.1.hum1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "tomcat10-jsp-3.1-api",
        "ecosystem": "Red Hat:hummingbird:1",
        "purl": "pkg:rpm/redhat/tomcat10-jsp-3.1-api"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:10.1.60-0.1.hum1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "tomcat10-lib",
        "ecosystem": "Red Hat:hummingbird:1",
        "purl": "pkg:rpm/redhat/tomcat10-lib"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:10.1.60-0.1.hum1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "tomcat10-servlet-6.0-api",
        "ecosystem": "Red Hat:hummingbird:1",
        "purl": "pkg:rpm/redhat/tomcat10-servlet-6.0-api"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:10.1.60-0.1.hum1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "tomcat10-user-instance",
        "ecosystem": "Red Hat:hummingbird:1",
        "purl": "pkg:rpm/redhat/tomcat10-user-instance"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:10.1.60-0.1.hum1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "tomcat10-webapps",
        "ecosystem": "Red Hat:hummingbird:1",
        "purl": "pkg:rpm/redhat/tomcat10-webapps"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:10.1.60-0.1.hum1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://access.redhat.com/errata/RHSA-2026:68257"
    },
    {
      "type": "ARTICLE",
      "url": "https://images.redhat.com/"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-68569"
    },
    {
      "type": "ARTICLE",
      "url": "https://access.redhat.com/security/updates/classification/"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-41284"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-79677"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-76183"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-78437"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-86350"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-87022"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-78383"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-77791"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-73581"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-75973"
    },
    {
      "type": "ARTICLE",
      "url": "https://access.redhat.com/security/cve/CVE-2026-77756"
    },
    {
      "type": "ADVISORY",
      "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68257.json"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476518"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41284"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41284"
    },
    {
      "type": "ARTICLE",
      "url": "https://lists.apache.org/thread/2nvqjr7ovjmvx2vbhb7s61ycd5msc8qc"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2524160"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68569"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68569"
    },
    {
      "type": "ARTICLE",
      "url": "https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2539356"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73581"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73581"
    },
    {
      "type": "ARTICLE",
      "url": "https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2539354"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75973"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75973"
    },
    {
      "type": "ARTICLE",
      "url": "https://lists.apache.org/thread/njjcdkkzqyzx4n3ffc4ffjmyh5mpl1gr"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2539355"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76183"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76183"
    },
    {
      "type": "ARTICLE",
      "url": "https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2539396"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77791"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77791"
    },
    {
      "type": "ARTICLE",
      "url": "https://lists.apache.org/thread/mb1pjjooqytrl6hbvbt3rw1lqwlon4cz"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2539486"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78383"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78383"
    },
    {
      "type": "ARTICLE",
      "url": "https://lists.apache.org/thread/tyqcqk99g7ghgk22641vf67vghcyswnw"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2539533"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78437"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78437"
    },
    {
      "type": "ARTICLE",
      "url": "https://lists.apache.org/thread/qkmsos3s8chn5053qr466rzwv6sk5gjg"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2539616"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79677"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79677"
    },
    {
      "type": "ARTICLE",
      "url": "http://www.openwall.com/lists/oss-security/2026/09/23/27"
    },
    {
      "type": "ARTICLE",
      "url": "https://lists.apache.org/thread/bzwps6ck4szf2hmksbbon3syyl9qnkv8"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2539370"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86350"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86350"
    },
    {
      "type": "ARTICLE",
      "url": "https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2539373"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87022"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87022"
    },
    {
      "type": "ARTICLE",
      "url": "https://lists.apache.org/thread/ypvlkjqsq0480fnk9jm6h9qllddwlw4w"
    }
  ]
}