CVE detail
CVE-2026-29146
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
20 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:39189access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:39188access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:38505access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29146.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comApr 9, 2026, 8:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2457020bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/security/cve/CVE-2026-29146access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:37137access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:37136access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:36879access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:36878access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:36877access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:36876access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:36790access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:36789access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:36788access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:36787access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:20406access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:20405access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 9, 2026, 8:16 PM - http://www.openwall.com/lists/oss-security/2026/04/09/24www.openwall.com
No excerpt available.
Exploitwww.openwall.comApr 9, 2026, 8:16 PM - https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0wlists.apache.org
No excerpt available.
Vendor Advisorylists.apache.orgApr 9, 2026, 8:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-21733CVSS 5.3 · Medium
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0…
- CVE-2026-59943CVSS 6.3 · Medium
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rende…
- CVE-2025-59177CVSS 6.8 · Medium
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to…
- CVE-2026-56537CVSS 3.5 · Low
HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request d…
- CVE-2026-66009CVSS 6.3 · Medium
Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public in…
- CVE-2026-66008CVSS 6.3 · Medium
Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion erro…