CVE-2026-29146

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
References
Link Resource
https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/04/09/24 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

History

14 Apr 2026, 12:56

Type Values Removed Values Added
CPE cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
References () https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w - () https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/04/09/24 - () http://www.openwall.com/lists/oss-security/2026/04/09/24 - Mailing List, Third Party Advisory
First Time Apache
Apache tomcat

10 Apr 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-209
CWE-642

10 Apr 2026, 00:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/04/09/24 -

09 Apr 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 20:16

Updated : 2026-04-14 12:56


NVD link : CVE-2026-29146

Mitre link : CVE-2026-29146

CVE.ORG link : CVE-2026-29146


JSON object : View

Products Affected

apache

  • tomcat
CWE
CWE-209

Generation of Error Message Containing Sensitive Information

CWE-642

External Control of Critical State Data