CVE-2026-29146
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
7.5
HIGH
CVSS 3.1
EPSS 12.9%
Description
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
How to fix CVE-2026-29146
To remediate CVE-2026-29146, upgrade the affected package to a fixed version below.
- —upgrade to 9.0.116 or later
- —no fix listed
- —no fix listed
- —upgrade to 9.0.70-2 or later
- —upgrade to 9.0.116 or later
- —upgrade to 9.0.116 or later
Is CVE-2026-29146 being exploited?
Moderate — EPSS is 12.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (6)
- >= 7.0.100, < 9.0.116, >= 10.0.0, < 10.1.53, >= 11.0.0, < 11.0.19
- from 0
- from 0
- from 0, < 9.0.70-2
- >= 9.0.13, < 9.0.116
- >= 9.0.13, < 9.0.116
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |