Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Avi Lumelsky

Researcher fromOligo Security
#35278of 56,330
7.8Total CVSS
Vulnerabilities · 1
PT-2026-31700
7.8
2026-03-23
Apache · Apache Tomcat · CVE-2026-29146
**Name of the Vulnerable Software and Affected Versions** Apache Tomcat versions 11.0.0-M1 through 11.0.18 Apache Tomcat versions 10.0.0-M1 through 10.1.52 Apache Tomcat versions 9.0.13 through 9.115 Apache Tomcat versions 8.5.38 through 8.5.100 Apache Tomcat versions 7.0.100 through 7.0.109 **Description** A Padding Oracle flaw exists in the `EncryptInterceptor` when using its default configuration. This issue stems from the use of Cipher Block Chaining (CBC) and deficiencies in the error reporting mechanism. A remote attacker can exploit these weaknesses in the encryption padding to decrypt sensitive information and gain unauthorized access to confidential data. **Recommendations** Upgrade Apache Tomcat versions 11.0.0-M1 through 11.0.18 to version 11.0.19. Upgrade Apache Tomcat versions 10.0.0-M1 through 10.1.52 to version 10.1.53. Upgrade Apache Tomcat versions 9.0.13 through 9.115 to version 9.0.116. At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 8.5.38 through 8.5.100. At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 7.0.100 through 7.0.109.