Описание
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-29146
- https://github.com/apache/tomcat/commit/0112ed22abfccc3d54e44d91eb08804d0886acd1
- https://github.com/apache/tomcat/commit/607ebc0fa522bd9e8c05517baa2d179bbd1e659c
- https://github.com/apache/tomcat/commit/6d955cceca841f2eabf2d6c46b59a8c7e1cd6eaa
- https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.53
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.116
- https://www.herodevs.com/vulnerability-directory/cve-2026-29146
- http://www.openwall.com/lists/oss-security/2026/04/09/24
Пакеты
org.apache.tomcat:tomcat-tribes
>= 9.0.13, < 9.0.116
9.0.116
org.apache.tomcat:tomcat-tribes
>= 10.1.50, < 10.1.53
10.1.53
org.apache.tomcat:tomcat-tribes
>= 11.0.0-M1, <= 11.0.18
11.0.20
org.apache.tomcat:tomcat
>= 9.0.13, < 9.0.116
9.0.116
org.apache.tomcat:tomcat
>= 10.1.50, < 10.1.53
10.1.53
org.apache.tomcat:tomcat
>= 11.0.0-M1, <= 11.0.18
11.0.20
org.apache.tomcat:tomcat-tribes
>= 8.5.38, <= 8.5.100
Отсутствует
org.apache.tomcat:tomcat
>= 8.5.38, <= 8.5.100
Отсутствует
org.apache.tomcat:tomcat-tribes
>= 7.0.100, <= 7.0.109
Отсутствует
org.apache.tomcat:tomcat
>= 7.0.100, <= 7.0.109
Отсутствует
Связанные уязвимости
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor wit ...
Уязвимость сервера приложений Apache Tomcat, связанная с недостатками механизма формирования отчетов об ошибках, позволяющая нарушителю осуществить атаку типа Padding Oracle (атаку с использованием «заполнения»)