PT-2026-31700 · Apache+3 · Apache Tomcat+3

·

CVE-2026-29146

·

Published

2026-03-23

·

Updated

2026-07-20

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.18 Apache Tomcat versions 10.0.0-M1 through 10.1.52 Apache Tomcat versions 9.0.13 through 9.115 Apache Tomcat versions 8.5.38 through 8.5.100 Apache Tomcat versions 7.0.100 through 7.0.109
Description A Padding Oracle flaw exists in the EncryptInterceptor when using its default configuration. This issue stems from the use of Cipher Block Chaining (CBC) and deficiencies in the error reporting mechanism. A remote attacker can exploit these weaknesses in the encryption padding to decrypt sensitive information and gain unauthorized access to confidential data.
Recommendations Upgrade Apache Tomcat versions 11.0.0-M1 through 11.0.18 to version 11.0.19. Upgrade Apache Tomcat versions 10.0.0-M1 through 10.1.52 to version 10.1.53. Upgrade Apache Tomcat versions 9.0.13 through 9.115 to version 9.0.116. At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 8.5.38 through 8.5.100. At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 7.0.100 through 7.0.109.

Exploit

Fix

DoS

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36788
ALSA-2026:36790
ALSA-2026:36879
ALSA-2026:37137
BDU:2026-05543
BIT-TOMCAT-2026-29146
CVE-2026-29146
GHSA-H468-7PVH-8VR8
MGASA-2026-0095
OESA-2026-1970
OPENSUSE-SU-2026:10547-1
OPENSUSE-SU-2026:10548-1
OPENSUSE-SU-2026:10549-1
OPENSUSE-SU-2026:20595-1
OPENSUSE-SU-2026:20611-1
OPENSUSE-SU-2026:20612-1
RHSA-2026:20405
RHSA-2026:36787
RHSA-2026:36788
RHSA-2026:36789
RHSA-2026:36876
RHSA-2026:36877
RHSA-2026:36878
RHSA-2026:36879
RHSA-2026:37136
RHSA-2026:37137
RHSA-2026:38505
SUSE-SU-2026:1558-1
SUSE-SU-2026:1572-1
SUSE-SU-2026:1603-1
SUSE-SU-2026:1604-1
SUSE-SU-2026:21366-1
SUSE-SU-2026:21378-1
SUSE-SU-2026:21379-1

Affected Products

Apache Tomcat
Confluence
Red Os
Rocky Linux