Vulnerability Description
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | >= 7.0.100, <= 7.0.109 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0wMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/04/09/24Mailing ListThird Party Advisory
FAQ
What is CVE-2026-29146?
CVE-2026-29146 is a vulnerability with a CVSS score of 7.5 (HIGH). Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9...
How severe is CVE-2026-29146?
CVE-2026-29146 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-29146?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat.