CVE-2026-29146

Aliases:GHSA-h468-7pvh-8vr8BIT-tomcat-2026-29146UBUNTU-CVE-2026-29146DEBIAN-CVE-2026-29146
Modified
Published: 09 Apr 2026, 19:21
Last modified:17 Aug 2026, 12:05

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
6.26% LOW
6% probability +2.76%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Apr 2026, 19:21
Published
Vulnerability first disclosed
17 Aug 2026, 12:05
Last Modified
Vulnerability information updated

Description

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

CVSS Metrics

  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 6.26% Percentile: 93%

Techniques & Countermeasures

  • CWE-209Generation of Error Message Containing Sensitive Information

    The product generates an error message that includes sensitive information about its environment, users, or associated data.

  • CWE-642External Control of Critical State Data

    The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.

  • CWE-1240Use of a Cryptographic Primitive with a Risky Implementation

    To fulfill the need for a cryptographic primitive, the product implements a cryptographic algorithm using a non-standard, unproven, or disallowed/non-compliant cryptographic implementation.

Affected Systems

  • apache software foundationapache tomcat

    ≥ 11.0.0-M1, ≤ 11.0.18 | ≥ 10.0.0-M1, ≤ 10.1.52 | ≥ 9.0.13, ≤ 9.0.115 | ≥ 8.5.38, ≤ 8.5.100 | ≥ 7.0.100, ≤ 7.0.109

  • apachetomcat

    ≥ 7.0.100, ≤ 7.0.109 | ≥ 8.5.38, ≤ 8.5.100 | ≥ 9.0.13, < 9.0.116 | ≥ 10.0.0, < 10.1.53 | ≥ 11.0.0, < 11.0.20

  • debiantomcat10

    < 10.1.55-1~deb12u1 | < 10.1.55-1~deb13u1 | < 10.1.54-1

  • debiantomcat11

    < 11.0.22-1~deb13u1 | < 11.0.21-1

  • debiantomcat9

    < 9.0.118-0+deb11u1 | < 9.0.70-2 | < 9.0.70-2 | < 9.0.70-2

  • ubuntutomcat10

    all | all | all

  • ubuntutomcat11

    all | all

  • ubuntutomcat8

    all

  • ubuntutomcat9

    all | all | all | all

  • org.apache.tomcattomcat

    ≥ 11.0.0-M1, < 11.0.19 | ≥ 9.0.13, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.0-M1, < 11.0.20 | ≥ 8.5.38, ≤ 8.5.100 | ≥ 7.0.100, ≤ 7.0.109

  • org.apache.tomcattomcat-catalina

    ≥ 9.0.13, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.0-M1, < 11.0.19

  • org.apache.tomcattomcat-tribes

    ≥ 9.0.13, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.0-M1, < 11.0.20 | ≥ 8.5.38, ≤ 8.5.100 | ≥ 7.0.100, ≤ 7.0.109

  • org.apache.tomcat.embedtomcat-embed-core

    ≥ 9.0.13, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.0-M1, < 11.0.19

References (32)