Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-29146

Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor (important)
Back to all
CVE

CVE-2026-29146

Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor (important)

DOCUMENTATION: A flaw was found in Apache Tomcat. This Padding Oracle vulnerability, present in the EncryptInterceptor with its default configuration, could allow a remote attacker to decrypt sensitive information. By exploiting weaknesses in the encryption padding, an attacker may be able to gain unauthorized access to data that should remain confidential. 

            STATEMENT: Important: A padding oracle vulnerability exists in Apache Tomcat's EncryptInterceptor when using its default configuration. This flaw could allow a remote attacker to decrypt sensitive information by exploiting weaknesses in the encryption padding. This vulnerability is not exploitable in any supported Red Hat Products. This is due to the fact EncryptInterceptor is a Tomcat component used to encrypt communication between different nodes in a cluster, however Tomcat's clustering is not tested and supported by Red Hat since Red Hat Enterprise Linux 7. More details about Tomcat's clustering in Red Hat supported products can be found at the following Solution page:

https://access.redhat.com/solutions/67862

            MITIGATION: This vulnerability can be mitigated by removing the affected jar file from the tomcat installation. It can be achieved by running the following command as root:

systemctl stop tomcat
rm -fv /usr/share/java/tomcat/catalina-tribes.jar
systemctl start tomcat

It's important to notice if the Tomcat instance is configured to run with clustering, this may lead to errors when restarting the tomcat service. Red Hat's distributed Apache Tomcat should not be run with Clustering enabled, so make sure to disable such configuration before proceed with the mitigation if that's the case.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
7.5
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
C
H
U
-
C
H
U
-

Related Resources

No items found.

References

https://access.redhat.com/security/cve/CVE-2026-29146

Severity

0

CVSS Score
0
10

Basic Information

Ecosystem
Base CVSS
0
EPSS Probability
0.12919%
EPSS Percentile
0.94214%
Introduced Version
0
Fix Available
10.1.55-1~deb12u1,9.0.70-2,9.0.118-0+deb11u1,10.1.55-1~deb13u1,11.0.22-1~deb13u1,1:9.0.117-1.amzn2023.0.1,1:10.1.54-1.amzn2023.0.1,0:9.0.117-1.amzn2.0.1,8.8.22-r0,8.6.39-r0,8.7.27-r0,2025.0.8-r10,2025.1.6-r8,2025.2.4-r4,2025.4.3-r5,2026.0.2-r5,2025.0.8-r12,2025.1.6-r9,2025.2.4-r5,2025.4.3-r6,2026.0.2-r6,3.2.0-r6,3.2.0-r2,5.5.0-r8,5.5.0-r4,4.3.1.1-r2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading