CVE-2026-29146

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

History

20 Jul 2026, 12:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:39188 -
  • () https://access.redhat.com/errata/RHSA-2026:39189 -

13 Jul 2026, 13:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:38505 -

09 Jul 2026, 13:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:36787 -
  • () https://access.redhat.com/errata/RHSA-2026:36788 -
  • () https://access.redhat.com/errata/RHSA-2026:36789 -
  • () https://access.redhat.com/errata/RHSA-2026:36790 -
  • () https://access.redhat.com/errata/RHSA-2026:36876 -
  • () https://access.redhat.com/errata/RHSA-2026:36877 -
  • () https://access.redhat.com/errata/RHSA-2026:36878 -
  • () https://access.redhat.com/errata/RHSA-2026:36879 -
  • () https://access.redhat.com/errata/RHSA-2026:37136 -
  • () https://access.redhat.com/errata/RHSA-2026:37137 -

30 Jun 2026, 03:18

Type Values Removed Values Added
CWE CWE-1240
References
  • () https://access.redhat.com/errata/RHSA-2026:20405 -
  • () https://access.redhat.com/errata/RHSA-2026:20406 -
  • () https://access.redhat.com/security/cve/CVE-2026-29146 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2457020 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29146.json -

14 Apr 2026, 12:56

Type Values Removed Values Added
First Time Apache
Apache tomcat
CPE cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
References () https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w - () https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/04/09/24 - () http://www.openwall.com/lists/oss-security/2026/04/09/24 - Mailing List, Third Party Advisory

10 Apr 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-209
CWE-642

10 Apr 2026, 00:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/04/09/24 -

09 Apr 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 20:16

Updated : 2026-07-20 12:18


NVD link : CVE-2026-29146

Mitre link : CVE-2026-29146

CVE.ORG link : CVE-2026-29146


JSON object : View

Products Affected

apache

  • tomcat
CWE
CWE-209

Generation of Error Message Containing Sensitive Information

CWE-642

External Control of Critical State Data

CWE-1240

Use of a Cryptographic Primitive with a Risky Implementation