Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
Summary
| CVE | CVE-2026-29146 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-09 20:16:24 UTC |
| Updated | 2026-07-20 12:18:25 UTC |
| Description | Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.001040000 probability, percentile 0.284770000 (date 2026-04-15)
Problem Types: CWE-209 | CWE-642 | CWE-1240 | Padding Oracle | CWE-209 CWE-209 Generation of Error Message Containing Sensitive Information | CWE-642 CWE-642 External Control of Critical State Data | CWE-1240 Use of a Cryptographic Primitive with a Risky Implementation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | ADP | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Tomcat | affected 11.0.0-M1 11.0.18 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 10.0.0-M1 10.1.52 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 9.0.13 9.0.115 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 8.5.38 8.5.100 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 7.0.100 7.0.109 semver | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | unaffected 1:10.1.49-3.el10_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | unaffected 1:9.0.117-2.el10_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | unaffected 1:10.1.36-2.el10_0 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | unaffected 1:9.0.87-6.el10_0 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | unaffected 0:7.0.76-18.el7_9 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | unaffected 1:9.0.87-2.el8_10 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | unaffected 1:9.0.87-2.el8_8 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions | unaffected 1:9.0.87-2.el8_8 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | unaffected 1:9.0.117-2.el9_8 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions | unaffected 1:9.0.87-2.el9_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions | unaffected 1:9.0.87-2.el9_4 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | unaffected 1:9.0.87-4.el9_6 * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6.2.3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6.2 On RHEL 10 | unaffected 0:10.1.49-13.redhat_00011.1.el10jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6.2 On RHEL 8 | unaffected 0:10.1.49-13.redhat_00011.1.el8jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6.2 On RHEL 9 | unaffected 0:10.1.49-13.redhat_00011.1.el9jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 7.0.0 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 7.0 On RHEL 10 | unaffected 0:11.0.21-5.redhat_00004.1.el10jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 7.0 On RHEL 8 | unaffected 0:11.0.21-5.redhat_00004.1.el8jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 7.0 On RHEL 9 | unaffected 0:11.0.21-5.redhat_00004.1.el9jws * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 6 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 5 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36877 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36878 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| www.openwall.com/lists/oss-security/2026/04/09/24 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:39188 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36787 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:38505 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36788 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:37137 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w | [email protected] | lists.apache.org | Mailing List, Vendor Advisory |
| access.redhat.com/errata/RHSA-2026:36790 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:20405 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:37136 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-29146 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36789 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29146.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36879 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36876 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:20406 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:39189 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Uri Katz and Avi Lumelsky (Oligo Security) (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-04-09T20:01:03.123Z | Reported to Red Hat. |
| ADP | 2026-04-09T19:21:57.289Z | Made public. |
Solutions
ADP: RHSA-2026:20405: Red Hat JBoss Web Server 6.2 on RHEL 10, Red Hat JBoss Web Server 6.2 on RHEL 8, Red Hat JBoss Web Server 6.2 on RHEL 9
ADP: RHSA-2026:39188: Red Hat JBoss Web Server 7.0 on RHEL 10, Red Hat JBoss Web Server 7.0 on RHEL 8, Red Hat JBoss Web Server 7.0 on RHEL 9
ADP: RHSA-2026:38505: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS)
ADP: RHSA-2026:36787: Red Hat Enterprise Linux AppStream EUS (v. 10.0)
ADP: RHSA-2026:36789: Red Hat Enterprise Linux AppStream EUS (v. 10.0)
ADP: RHSA-2026:36788: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:36790: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:37137: Red Hat Enterprise Linux AppStream (v. 8)
ADP: RHSA-2026:37136: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8)
ADP: RHSA-2026:36878: Red Hat Enterprise Linux AppStream E4S (v.9.2)
ADP: RHSA-2026:36876: Red Hat Enterprise Linux AppStream E4S (v.9.4)
ADP: RHSA-2026:36877: Red Hat Enterprise Linux AppStream EUS (v.9.6)
ADP: RHSA-2026:36879: Red Hat Enterprise Linux AppStream (v. 9)
ADP: RHSA-2026:20406: Red Hat JBoss Web Server 6.2.3
ADP: RHSA-2026:39189: Red Hat JBoss Web Server 7.0.0
Workarounds
ADP: This vulnerability can be mitigated by removing the affected jar file from the tomcat installation. It can be achieved by running the following command as root: ~~~ systemctl stop tomcat rm -fv /usr/share/java/tomcat/catalina-tribes.jar systemctl start tomcat ~~~ It's important to notice if the Tomcat instance is configured to run with clustering, this may lead to errors when restarting the tomcat service. Red Hat's distributed Apache Tomcat should not be run with Clustering enabled, so make sure to disable such configuration before proceed with the mitigation if that's the case.