CVE-2026-29146
Vulnerability Summary
Timeline
Description
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
CVSS Metrics
- v4.0•HIGH•Score: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 6.26%• Percentile: 93%
Techniques & Countermeasures
- CWE-209•Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
- CWE-642•External Control of Critical State Data
The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.
- CWE-1240•Use of a Cryptographic Primitive with a Risky Implementation
To fulfill the need for a cryptographic primitive, the product implements a cryptographic algorithm using a non-standard, unproven, or disallowed/non-compliant cryptographic implementation.
Affected Systems
- apache software foundation•apache tomcat
≥ 11.0.0-M1, ≤ 11.0.18 | ≥ 10.0.0-M1, ≤ 10.1.52 | ≥ 9.0.13, ≤ 9.0.115 | ≥ 8.5.38, ≤ 8.5.100 | ≥ 7.0.100, ≤ 7.0.109
- apache•tomcat
≥ 7.0.100, ≤ 7.0.109 | ≥ 8.5.38, ≤ 8.5.100 | ≥ 9.0.13, < 9.0.116 | ≥ 10.0.0, < 10.1.53 | ≥ 11.0.0, < 11.0.20
- debian•tomcat10
< 10.1.55-1~deb12u1 | < 10.1.55-1~deb13u1 | < 10.1.54-1
- debian•tomcat11
< 11.0.22-1~deb13u1 | < 11.0.21-1
- debian•tomcat9
< 9.0.118-0+deb11u1 | < 9.0.70-2 | < 9.0.70-2 | < 9.0.70-2
- ubuntu•tomcat10
all | all | all
- ubuntu•tomcat11
all | all
- ubuntu•tomcat8
all
- ubuntu•tomcat9
all | all | all | all
- org.apache.tomcat•tomcat
≥ 11.0.0-M1, < 11.0.19 | ≥ 9.0.13, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.0-M1, < 11.0.20 | ≥ 8.5.38, ≤ 8.5.100 | ≥ 7.0.100, ≤ 7.0.109
- org.apache.tomcat•tomcat-catalina
≥ 9.0.13, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.0-M1, < 11.0.19
- org.apache.tomcat•tomcat-tribes
≥ 9.0.13, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.0-M1, < 11.0.20 | ≥ 8.5.38, ≤ 8.5.100 | ≥ 7.0.100, ≤ 7.0.109
- org.apache.tomcat.embed•tomcat-embed-core
≥ 9.0.13, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.0-M1, < 11.0.19
References (32)
- https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w
- http://www.openwall.com/lists/oss-security/2026/04/09/24
- https://nvd.nist.gov/vuln/detail/CVE-2026-29146
- https://github.com/apache/tomcat
- https://github.com/apache/tomcat/commit/0112ed22abfccc3d54e44d91eb08804d0886acd1
- https://github.com/apache/tomcat/commit/607ebc0fa522bd9e8c05517baa2d179bbd1e659c
- https://github.com/apache/tomcat/commit/6d955cceca841f2eabf2d6c46b59a8c7e1cd6eaa
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.53
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.116
- https://www.herodevs.com/vulnerability-directory/cve-2026-29146
- https://access.redhat.com/security/cve/CVE-2026-29146
- https://bugzilla.redhat.com/show_bug.cgi?id=2457020
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29146.json
- https://access.redhat.com/errata/RHSA-2026:20405
- https://access.redhat.com/errata/RHSA-2026:20406
- https://access.redhat.com/errata/RHSA-2026:36787
- https://access.redhat.com/errata/RHSA-2026:36789
- https://access.redhat.com/errata/RHSA-2026:36788
- https://access.redhat.com/errata/RHSA-2026:36790
- https://access.redhat.com/errata/RHSA-2026:37137
- https://access.redhat.com/errata/RHSA-2026:37136
- https://access.redhat.com/errata/RHSA-2026:36878
- https://access.redhat.com/errata/RHSA-2026:36876
- https://access.redhat.com/errata/RHSA-2026:36877
- https://access.redhat.com/errata/RHSA-2026:36879
- https://access.redhat.com/errata/RHSA-2026:38505
- https://access.redhat.com/errata/RHSA-2026:39188
- https://access.redhat.com/errata/RHSA-2026:39189
- https://ubuntu.com/security/CVE-2026-29146
- https://www.cve.org/CVERecord?id=CVE-2026-29146
- https://security-tracker.debian.org/tracker/CVE-2026-29146