VDB

DEBIAN-CVE-2026-29146

DEBIAN-CVE-2026-29146 PUBLISHED CVSS 7.5 HIGH

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:14tomcat90, 0
Debian:13tomcat1010.1.54-1, 10.1.52-2, 10.1.52-1
Debian:14tomcat1010.1.52-2, 10.1.52-1, 10.1.52-1
Debian:11tomcat99.0.43-2, 9.0.43-2, 9.0.43-2
Debian:13tomcat1111.0.15-1~deb13u1, 0, 11.0.6-1
Debian:14tomcat1111.0.15-1, 11.0.6-1, 11.0.18-1
Debian:12tomcat90, 0
Debian:12tomcat10*, 10.1.30-1, *
Debian:13tomcat90, 0

Timeline

  • Apr 9, 2026 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›