HIGH7.5
GHSA-69cc-cv78-qc8g
Apache Tomcat: Configured cipher preference order not preserved
Quick fix
GHSA-69cc-cv78-qc8g — org.apache.tomcat:tomcat-coyote: upgrade to the fixed version with the command below.
# pom.xml: bump <version>9.0.116</version> for org.apache.tomcat:tomcat-coyoteDetails
Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.tomcat:tomcat-coyote
Introduced in:
9.0.114Fixed in: 9.0.116Fix
# pom.xml: bump <version>9.0.116</version> for org.apache.tomcat:tomcat-coyoteMaven/org.apache.tomcat:tomcat-coyote
Introduced in:
10.1.51Fixed in: 10.1.53Fix
# pom.xml: bump <version>10.1.53</version> for org.apache.tomcat:tomcat-coyoteMaven/org.apache.tomcat:tomcat-coyote
Introduced in:
11.0.16Fixed in: 11.0.20Fix
# pom.xml: bump <version>11.0.20</version> for org.apache.tomcat:tomcat-coyoteMaven/org.apache.tomcat:tomcat
Introduced in:
9.0.114Fixed in: 9.0.116Fix
# pom.xml: bump <version>9.0.116</version> for org.apache.tomcat:tomcatMaven/org.apache.tomcat:tomcat
Introduced in:
10.1.51Fixed in: 10.1.53Fix
# pom.xml: bump <version>10.1.53</version> for org.apache.tomcat:tomcatMaven/org.apache.tomcat:tomcat
Introduced in:
11.0.16Fixed in: 11.0.20Fix
# pom.xml: bump <version>11.0.20</version> for org.apache.tomcat:tomcatMaven/org.apache.tomcat.embed:tomcat-embed-core
Introduced in:
9.0.114Fixed in: 9.0.116Fix
# pom.xml: bump <version>9.0.116</version> for org.apache.tomcat.embed:tomcat-embed-coreMaven/org.apache.tomcat.embed:tomcat-embed-core
Introduced in:
10.1.51Fixed in: 10.1.53Fix
# pom.xml: bump <version>10.1.53</version> for org.apache.tomcat.embed:tomcat-embed-coreMaven/org.apache.tomcat.embed:tomcat-embed-core
Introduced in:
11.0.16Fixed in: 11.0.20Fix
# pom.xml: bump <version>11.0.20</version> for org.apache.tomcat.embed:tomcat-embed-coreReferences
- https://nvd.nist.gov/vuln/detail/CVE-2026-29129[ADVISORY]
- https://github.com/apache/tomcat/commit/5cfa876d73f1ff5f4dc8309c4320f684cbeff74e[WEB]
- https://github.com/apache/tomcat/commit/6db238562ec36ab1106db4d04843f8b33e7a0c06[WEB]
- https://github.com/apache/tomcat/commit/8d69b33764dba81dce89e3a768de6093a35620ae[WEB]
- https://github.com/apache/tomcat[PACKAGE]
- https://lists.apache.org/thread/r4h1t6f8xhxsxfm6c2z5cprolsosho3f[WEB]
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.53[WEB]
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20[WEB]
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.116[WEB]
- http://www.openwall.com/lists/oss-security/2026/04/09/22[WEB]