CVE-2026-29129

HIGH7.5EPSS 0.03%

Apache Tomcat: Configured cipher preference order not preserved

發布日:2026/4/9修改日:2026/5/20
也稱為:GHSA-69cc-cv78-qc8gBIT-tomcat-2026-29129CGA-pfh5-hmhh-7hcx

描述

Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

受影響套件(7)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

參考連結(11)