Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-34486

Опубликовано: 09 апр. 2026
Источник: debian
EPSS Средний

Описание

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat11not-affectedpackage
tomcat10not-affectedpackage
tomcat9not-affectedpackage

Примечания

  • Fixed by: https://github.com/apache/tomcat/commit/1fab40ccc752e22639eccfe290d5624afad7eccd (11.0.21)

  • Fixed by: https://github.com/apache/tomcat/commit/55f3eb9148233054fccfdf761141c6894a050be1 (10.1.54)

  • Fixed by: https://github.com/apache/tomcat/commit/776e12b3e2b0b4507b8a3b62c187ceb0b74bf418 (9.0.117)

EPSS

Процентиль: 99%
0.42627
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
redhat
4 месяца назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
nvd
4 месяца назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
github
4 месяца назад

Apache Tomcat Missing Encryption of Sensitive Data vulnerability

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостатками шифрования конфиденциальных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 99%
0.42627
Средний