CVE-2026-29129
Vulnerability Summary
Timeline
Description
Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 0.26%• Percentile: 18%
Techniques & Countermeasures
- CWE-327•Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
Affected Systems
- apache software foundation•apache tomcat
≥ 11.0.16, ≤ 11.0.18 | ≥ 10.1.51, ≤ 10.1.52 | ≥ 9.0.114, ≤ 9.0.115
- apache•tomcat
≥ 9.0.114, < 9.0.116 | ≥ 10.1.51, < 10.1.53 | ≥ 11.0.16, < 11.0.20
- debian•tomcat10
< 10.1.55-1~deb12u1 | < 10.1.55-1~deb13u1 | < 10.1.54-1
- debian•tomcat11
< 11.0.22-1~deb13u1 | < 11.0.21-1
- debian•tomcat9
< 9.0.118-0+deb11u1 | < 9.0.70-2 | < 9.0.70-2 | < 9.0.70-2
- org.apache.tomcat•tomcat
≥ 9.0.114, < 9.0.116 | ≥ 10.1.51, < 10.1.53 | ≥ 11.0.16, < 11.0.20
- org.apache.tomcat•tomcat-catalina
≥ 9.0.114, < 9.0.116 | ≥ 10.1.51, < 10.1.53 | ≥ 11.0.16, < 11.0.20
- org.apache.tomcat•tomcat-coyote
≥ 9.0.114, < 9.0.116 | ≥ 10.1.51, < 10.1.53 | ≥ 11.0.16, < 11.0.20
- org.apache.tomcat.embed•tomcat-embed-core
≥ 9.0.114, < 9.0.116 | ≥ 10.1.51, < 10.1.53 | ≥ 11.0.16, < 11.0.20
References (11)
- https://lists.apache.org/thread/r4h1t6f8xhxsxfm6c2z5cprolsosho3f
- http://www.openwall.com/lists/oss-security/2026/04/09/22
- https://nvd.nist.gov/vuln/detail/CVE-2026-29129
- https://github.com/apache/tomcat
- https://github.com/apache/tomcat/commit/5cfa876d73f1ff5f4dc8309c4320f684cbeff74e
- https://github.com/apache/tomcat/commit/6db238562ec36ab1106db4d04843f8b33e7a0c06
- https://github.com/apache/tomcat/commit/8d69b33764dba81dce89e3a768de6093a35620ae
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.53
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.116
- https://security-tracker.debian.org/tracker/CVE-2026-29129