GHSA-h468-7pvh-8vr8
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
Quick fix
GHSA-h468-7pvh-8vr8 — org.apache.tomcat:tomcat-tribes: upgrade to the fixed version with the command below.
# pom.xml: bump <version>9.0.116</version> for org.apache.tomcat:tomcat-tribesDetails
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
9.0.13Fixed in: 9.0.116# pom.xml: bump <version>9.0.116</version> for org.apache.tomcat:tomcat-tribes10.1.50Fixed in: 10.1.53# pom.xml: bump <version>10.1.53</version> for org.apache.tomcat:tomcat-tribes11.0.0-M1Fixed in: 11.0.20# pom.xml: bump <version>11.0.20</version> for org.apache.tomcat:tomcat-tribes9.0.13Fixed in: 9.0.116# pom.xml: bump <version>9.0.116</version> for org.apache.tomcat:tomcat10.1.50Fixed in: 10.1.53# pom.xml: bump <version>10.1.53</version> for org.apache.tomcat:tomcat11.0.0-M1Fixed in: 11.0.20# pom.xml: bump <version>11.0.20</version> for org.apache.tomcat:tomcat8.5.38No fixed version published yet for org.apache.tomcat:tomcat-tribes (maven). Pin to a known-safe version or switch to an alternative.
8.5.38No fixed version published yet for org.apache.tomcat:tomcat (maven). Pin to a known-safe version or switch to an alternative.
7.0.100No fixed version published yet for org.apache.tomcat:tomcat-tribes (maven). Pin to a known-safe version or switch to an alternative.
7.0.100No fixed version published yet for org.apache.tomcat:tomcat (maven). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-29146[ADVISORY]
- https://github.com/apache/tomcat/commit/0112ed22abfccc3d54e44d91eb08804d0886acd1[WEB]
- https://github.com/apache/tomcat/commit/607ebc0fa522bd9e8c05517baa2d179bbd1e659c[WEB]
- https://github.com/apache/tomcat/commit/6d955cceca841f2eabf2d6c46b59a8c7e1cd6eaa[WEB]
- https://github.com/apache/tomcat[PACKAGE]
- https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w[WEB]
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.53[WEB]
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20[WEB]
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.116[WEB]
- https://www.herodevs.com/vulnerability-directory/cve-2026-29146[WEB]
- http://www.openwall.com/lists/oss-security/2026/04/09/24[WEB]