Skip to main content
EPSS 8.8%top 5.1%

Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default (CVE-2026-29146)

0
High
Published: 04/13/2026 (04/13/2026, 16:01:34 UTC)
Source: GCVE Database
Product: tomcat

Description

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0 through 11.0.18, from 10.0.0 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

Affected software

Ubuntu:Pro:18.04:LTSmore threats →ghsa
tomcat8
pkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionic
Affected versions
=8.5.21-1ubuntu1=8.5.29-1=8.5.30-1=8.5.30-1ubuntu1=8.5.30-1ubuntu1.2=8.5.30-1ubuntu1.3=8.5.30-1ubuntu1.4=8.5.39-1ubuntu1~18.04.1=8.5.39-1ubuntu1~18.04.2=8.5.39-1ubuntu1~18.04.3=8.5.39-1ubuntu1~18.04.3+esm1=8.5.39-1ubuntu1~18.04.3+esm2=8.5.39-1ubuntu1~18.04.3+esm3=8.5.39-1ubuntu1~18.04.3+esm4=8.5.39-1ubuntu1~18.04.3+esm5=8.5.39-1ubuntu1~18.04.3+esm6
Ubuntu:Pro:18.04:LTSmore threats →ghsa
tomcat9
pkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionic
Affected versions
=9.0.16-3~18.04.1=9.0.16-3ubuntu0.18.04.1=9.0.16-3ubuntu0.18.04.2=9.0.16-3ubuntu0.18.04.2+esm1=9.0.16-3ubuntu0.18.04.2+esm2=9.0.16-3ubuntu0.18.04.2+esm3=9.0.16-3ubuntu0.18.04.2+esm4=9.0.16-3ubuntu0.18.04.2+esm5=9.0.16-3ubuntu0.18.04.2+esm6=9.0.16-3ubuntu0.18.04.2+esm7=9.0.16-3ubuntu0.18.04.2+esm8
Ubuntu:Pro:20.04:LTSmore threats →ghsa
tomcat9
pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focal
Affected versions
=9.0.24-1=9.0.27-1=9.0.31-1=9.0.31-1ubuntu0.1=9.0.31-1ubuntu0.2=9.0.31-1ubuntu0.3=9.0.31-1ubuntu0.4=9.0.31-1ubuntu0.5=9.0.31-1ubuntu0.6=9.0.31-1ubuntu0.7=9.0.31-1ubuntu0.8=9.0.31-1ubuntu0.9=9.0.31-1ubuntu0.9+esm1=9.0.31-1ubuntu0.9+esm2=9.0.31-1ubuntu0.9+esm3
Ubuntu:Pro:22.04:LTSmore threats →ghsa
tomcat9
pkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammy
Affected versions
=9.0.43-3=9.0.54-1=9.0.55-1=9.0.58-1=9.0.58-1ubuntu0.1=9.0.58-1ubuntu0.1+esm1=9.0.58-1ubuntu0.1+esm2=9.0.58-1ubuntu0.1+esm3=9.0.58-1ubuntu0.1+esm4=9.0.58-1ubuntu0.2=9.0.58-1ubuntu0.2+esm1=9.0.58-1ubuntu0.2+esm2=9.0.58-1ubuntu0.2+esm3=9.0.58-1ubuntu0.2+esm4
Ubuntu:Pro:24.04:LTSmore threats →ghsa
tomcat10
pkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/noble
Affected versions
=10.1.10-1=10.1.14-1=10.1.15-1=10.1.16-1=10.1.16-1ubuntu0.1~esm1=10.1.16-1ubuntu0.1~esm2=10.1.16-1ubuntu0.1~esm3=10.1.16-1ubuntu0.1~esm4
Ubuntu:Pro:24.04:LTSmore threats →ghsa
tomcat9
pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/noble
Affected versions
=9.0.70-1ubuntu1=9.0.70-2=9.0.70-2ubuntu0.1=9.0.70-2ubuntu0.1+esm1=9.0.70-2ubuntu0.1+esm2=9.0.70-2ubuntu0.1+esm3
Ubuntu:25.10more threats →ghsa
tomcat10
pkg:deb/ubuntu/[email protected]?arch=source&distro=questing
Affected versions
=10.1.35-1=10.1.40-1=10.1.40-1ubuntu1=10.1.40-1ubuntu1.25.10.1
Ubuntu:25.10more threats →ghsa
tomcat11
pkg:deb/ubuntu/[email protected]?arch=source&distro=questing
Affected versions
=11.0.6-1
Ubuntu:25.10more threats →ghsa
tomcat9
pkg:deb/ubuntu/[email protected]?arch=source&distro=questing
Affected versions
=9.0.70-2ubuntu1.1=9.0.70-2ubuntu2=9.0.70-2ubuntu3=9.0.95-1ubuntu1=9.0.95-1ubuntu1.1
Ubuntu:26.04:LTSmore threats →ghsa
tomcat10
pkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolute
Affected versions
=10.1.40-1ubuntu1=10.1.40-1ubuntu1.26.04.1=10.1.55-1ubuntu2~26.04.1
Ubuntu:26.04:LTSmore threats →ghsa
tomcat9
pkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolute
Affected versions
=9.0.95-1ubuntu1=9.0.111-1=9.0.115-1=9.0.115-1ubuntu0.1=9.0.118-1~26.04.1
Ubuntu:26.04:LTSmore threats →ghsa
tomcat11
pkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolute
Affected versions
=11.0.6-1=11.0.11-1=11.0.15-1=11.0.18-1=11.0.18-1ubuntu0.1~esm1=11.0.22-2ubuntu2~26.04.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 19:22:07 UTC

Technical Analysis

CVE-2026-29146 identifies a Padding Oracle vulnerability in the EncryptInterceptor component of Apache Tomcat. This vulnerability arises from weaknesses in the encryption padding mechanism used by EncryptInterceptor in its default configuration, potentially allowing remote attackers to decrypt sensitive data. The affected versions span multiple major releases of Apache Tomcat: from 7.0.100 to 7.0.109, 8.5.38 to 8.5.100, 9.0.13 to 9.0.115, 10.0.0-M1 to 10.1.52, and 11.0.0-M1 to 11.0.18. Red Hat's advisory clarifies that this vulnerability is not exploitable in their supported products due to the lack of support for Tomcat clustering, which is the feature that uses EncryptInterceptor. Mitigation can be achieved by removing the catalina-tribes.jar file from the Tomcat installation if clustering is not required, noting that enabling clustering after this removal may cause service errors. Official fixes are available in Apache Tomcat versions 11.0.19, 10.1.53, and 9.0.116. The CVSS v3.1 base score is 7.5 (high severity), reflecting network attack vector, low complexity, no privileges or user interaction required, unchanged scope, and high confidentiality impact without integrity or availability impact.

Potential Impact

The vulnerability allows a remote attacker to decrypt sensitive information by exploiting the padding oracle weakness in the EncryptInterceptor component of Apache Tomcat. This compromises confidentiality but does not affect integrity or availability. Red Hat products are not vulnerable in practice because Tomcat clustering is unsupported and untested in their distributions, effectively mitigating the risk in those environments.

Mitigation Recommendations

Red Hat advises that this vulnerability is not exploitable in their supported products due to the lack of support for Tomcat clustering. For environments where Tomcat clustering is not used, the vulnerability can be mitigated by removing the affected jar file (catalina-tribes.jar) from the Tomcat installation. This can be done by stopping the Tomcat service, deleting the jar file, and restarting the service. If clustering is enabled, it should be disabled before applying this mitigation to avoid service errors. Additionally, upgrading to Apache Tomcat versions 11.0.19, 10.1.53, or 9.0.116, which include the official fix, is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
UBUNTU-CVE-2026-29146
Osv Schema Version
1.7.0
Ecosystems
["Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a58b4d868715ace43dabc09

Added to database: 07/16/2026, 10:39:20 UTC

Last enriched: 08/17/2026, 19:22:07 UTC

Last updated: 09/14/2026, 10:01:30 UTC

Views: 51

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses