Apache · Apache Tomcat · CVE-2026-29146
**Name of the Vulnerable Software and Affected Versions**
Apache Tomcat versions 11.0.0-M1 through 11.0.18
Apache Tomcat versions 10.0.0-M1 through 10.1.52
Apache Tomcat versions 9.0.13 through 9.115
Apache Tomcat versions 8.5.38 through 8.5.100
Apache Tomcat versions 7.0.100 through 7.0.109
**Description**
A Padding Oracle flaw exists in the `EncryptInterceptor` when using its default configuration. This issue stems from the use of Cipher Block Chaining (CBC) and deficiencies in the error reporting mechanism. A remote attacker can exploit these weaknesses in the encryption padding to decrypt sensitive information and gain unauthorized access to confidential data.
**Recommendations**
Upgrade Apache Tomcat versions 11.0.0-M1 through 11.0.18 to version 11.0.19.
Upgrade Apache Tomcat versions 10.0.0-M1 through 10.1.52 to version 10.1.53.
Upgrade Apache Tomcat versions 9.0.13 through 9.115 to version 9.0.116.
At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 8.5.38 through 8.5.100.
At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 7.0.100 through 7.0.109.