{"id":"CVE-2026-29146","aliases":["BIT-tomcat-2026-29146","GHSA-h468-7pvh-8vr8"],"url":"https://o3.security/vulnerability/CVE-2026-29146","summary":"Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default","details":"Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.\n\nUsers are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.","published":"2026-04-09T19:21:57.289Z","modified":"2026-08-18T03:31:20.247247524Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.0885,"percentile":0.94931,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat-tribes","fixedVersion":"9.0.116"},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat-tribes","fixedVersion":"10.1.53"},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat-tribes","fixedVersion":"11.0.20"},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat","fixedVersion":"9.0.116"},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat","fixedVersion":"10.1.53"},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat","fixedVersion":"11.0.20"},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat-tribes","fixedVersion":null},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat","fixedVersion":null},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat-tribes","fixedVersion":null},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat","fixedVersion":null}],"fix":{"url":"https://github.com/apache/tomcat/commit/0112ed22abfccc3d54e44d91eb08804d0886acd1","label":"apache/tomcat@0112ed2"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/09/24"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29146.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:20405"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:20406"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36787"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36788"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36789"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36790"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36876"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36877"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36878"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36879"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37136"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37137"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:38505"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:39188"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:39189"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-29146"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29146.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29146"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2457020"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/0112ed22abfccc3d54e44d91eb08804d0886acd1"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/607ebc0fa522bd9e8c05517baa2d179bbd1e659c"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/6d955cceca841f2eabf2d6c46b59a8c7e1cd6eaa"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.53"},{"type":"WEB","url":"https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20"},{"type":"WEB","url":"https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.116"},{"type":"WEB","url":"https://www.herodevs.com/vulnerability-directory/cve-2026-29146"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T03:31:20.247247524Z"}}