CVE-2026-29146
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-29146
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2026-29146.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | fixed | 9.0.70-2 |
| debian | forky | fixed | 10.1.54-1 |
| debian | sid | fixed | 10.1.54-1 |
| debian | trixie | fixed | 9.0.70-2 |
| debian | bullseye | fixed | 9.0.70-2 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.tomcat:tomcat-tribes | >=9.0.13,<9.0.116 | 9.0.116 |
| Maven | org.apache.tomcat:tomcat-tribes | >=10.1.50,<10.1.53 | 10.1.53 |
| Maven | org.apache.tomcat:tomcat-tribes | >=11.0.0-M1,<11.0.20 | 11.0.20 |
| Maven | org.apache.tomcat:tomcat | >=9.0.13,<9.0.116 | 9.0.116 |
| Maven | org.apache.tomcat:tomcat | >=10.1.50,<10.1.53 | 10.1.53 |
| Maven | org.apache.tomcat:tomcat | >=11.0.0-M1,<11.0.20 | 11.0.20 |
| Maven | org.apache.tomcat:tomcat-tribes | >=8.5.38,<=8.5.100 | |
| Maven | org.apache.tomcat:tomcat | >=8.5.38,<=8.5.100 | |
| Maven | org.apache.tomcat:tomcat-tribes | >=7.0.100,<=7.0.109 | |
| Maven | org.apache.tomcat:tomcat | >=7.0.100,<=7.0.109 | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| gcp | | |
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-29146
- https://github.com/apache/tomcat/commit/0112ed22abfccc3d54e44d91eb08804d0886acd1
- https://github.com/apache/tomcat/commit/607ebc0fa522bd9e8c05517baa2d179bbd1e659c
- https://github.com/apache/tomcat/commit/6d955cceca841f2eabf2d6c46b59a8c7e1cd6eaa
- https://github.com/apache/tomcat
- https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.53
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.116
- https://www.herodevs.com/vulnerability-directory/cve-2026-29146
- http://www.openwall.com/lists/oss-security/2026/04/09/24
- https://www.suse.com/security/cve/CVE-2026-29146.html
- https://security-tracker.debian.org/tracker/CVE-2026-29146
Verify integrity in audit chain (admin only). AS-IS.