CVE-2026-29146
Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
7.5
HIGH
CVSS 3.1
EPSS 5.0%
Description
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0 through 11.0.18, from 10.0.0 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
How to fix CVE-2026-29146
To remediate CVE-2026-29146, upgrade the affected package to a fixed version below.
- —upgrade to 9.0.116 or later
Is CVE-2026-29146 being exploited?
Moderate — EPSS is 5.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 7.0.100, < 9.0.116, >= 10.0.0, < 10.1.53, >= 11.0.0, < 11.0.19
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |