{"id":"CVE-2026-29146","title":"Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 thr…","summary":"Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 thr…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-209","CWE-642","CWE-1240"],"vendor":"apache","product":"tomcat","affected":["tomcat >= 7.0.100, <= 7.0.109","tomcat >= 8.5.38, <= 8.5.100","tomcat >= 9.0.13, < 9.0.116","tomcat >= 10.0.0, < 10.1.53","tomcat >= 11.0.0, < 11.0.20"],"patched":["tomcat 11.0.20"],"published":"2026-04-09","updated":"2026-07-09","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-29146","references":[{"url":"https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/04/09/24","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2026:20405","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20406","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36787","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36788","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36789","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36790","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36876","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36877","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36878","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36879","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:37136","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:37137","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-29146","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2457020","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29146.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd"],"epss":0.0885,"epssPercentile":0.94973,"ingestedAt":"2026-07-10T01:55:23.151Z","slug":"CVE-2026-29146","body":"## Overview\n\nPadding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.\n\nUsers are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.\n\n## Affected\n\n- `tomcat >= 7.0.100, <= 7.0.109`\n- `tomcat >= 8.5.38, <= 8.5.100`\n- `tomcat >= 9.0.13, < 9.0.116`\n- `tomcat >= 10.0.0, < 10.1.53`\n- `tomcat >= 11.0.0, < 11.0.20`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tomcat 11.0.20`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":41.3,"likelihood":1.8,"exploitation":0,"ransomware":0},"changes":[]}