---
id: CVE-2026-29146
title: >-
  Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with
  default configuration.


  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from
  10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 thr…
summary: >-
  Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with
  default configuration.


  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from
  10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 thr…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-209
  - CWE-642
  - CWE-1240
vendor: apache
product: tomcat
affected:
  - 'tomcat >= 7.0.100, <= 7.0.109'
  - 'tomcat >= 8.5.38, <= 8.5.100'
  - 'tomcat >= 9.0.13, < 9.0.116'
  - 'tomcat >= 10.0.0, < 10.1.53'
  - 'tomcat >= 11.0.0, < 11.0.20'
patched:
  - tomcat 11.0.20
published: '2026-04-09'
updated: '2026-07-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-29146'
references:
  - url: 'https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/09/24'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:20405'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:20406'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36787'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36788'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36789'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36790'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36876'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36877'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36878'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36879'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37136'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37137'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-29146'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2457020'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29146.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.02887
epssPercentile: 0.86301
ingestedAt: '2026-07-10T01:55:23.151Z'
---

## Overview

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.

Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

## Affected

- `tomcat >= 7.0.100, <= 7.0.109`
- `tomcat >= 8.5.38, <= 8.5.100`
- `tomcat >= 9.0.13, < 9.0.116`
- `tomcat >= 10.0.0, < 10.1.53`
- `tomcat >= 11.0.0, < 11.0.20`

## Remediation

Upgrade past the affected range:

- `tomcat 11.0.20`
