Vulnerability Description
Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | >= 9.0.114, < 9.0.116 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/r4h1t6f8xhxsxfm6c2z5cprolsosho3fMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/04/09/22Mailing ListThird Party Advisory
FAQ
What is CVE-2026-29129?
CVE-2026-29129 is a vulnerability with a CVSS score of 7.5 (HIGH). Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0...
How severe is CVE-2026-29129?
CVE-2026-29129 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-29129?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat.