CVE-2026-29146

medium Apache
EPSS Score
6.3%
Exploitation probability in 30 days
Top 7% most likely to be exploited
Published: April 9, 2026 (151 days ago)
Last Modified: August 17, 2026
Vendor: Apache
Source: MITRE

Description

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

Affected Products

Apache Software Foundation Apache Tomcat

References