{
  "threat_severity" : "Important",
  "public_date" : "2026-04-09T19:21:57Z",
  "bugzilla" : {
    "description" : "Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor",
    "id" : "2457020",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2457020"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-1240",
  "details" : [ "Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.\nUsers are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.", "A flaw was found in Apache Tomcat. This Padding Oracle vulnerability, present in the EncryptInterceptor with its default configuration, could allow a remote attacker to decrypt sensitive information. By exploiting weaknesses in the encryption padding, an attacker may be able to gain unauthorized access to data that should remain confidential." ],
  "statement" : "Important: A padding oracle vulnerability exists in Apache Tomcat's EncryptInterceptor when using its default configuration. This flaw could allow a remote attacker to decrypt sensitive information by exploiting weaknesses in the encryption padding. This vulnerability is not exploitable in any supported Red Hat Products. This is due to the fact EncryptInterceptor is a Tomcat component used to encrypt communication between different nodes in a cluster, however Tomcat's clustering is not tested and supported by Red Hat since Red Hat Enterprise Linux 7. More details about Tomcat's clustering in Red Hat supported products can be found at the following Solution page:\n~~~\nhttps://access.redhat.com/solutions/67862\n~~~",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36788",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "tomcat-1:10.1.49-3.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36790",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "tomcat9-1:9.0.117-2.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36787",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "tomcat-1:10.1.36-2.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36789",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "tomcat9-1:9.0.87-6.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
    "release_date" : "2026-07-13T00:00:00Z",
    "advisory" : "RHSA-2026:38505",
    "cpe" : "cpe:/o:redhat:rhel_els:7",
    "package" : "tomcat-0:7.0.76-18.el7_9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-09T00:00:00Z",
    "advisory" : "RHSA-2026:37137",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "tomcat-1:9.0.87-2.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-07-09T00:00:00Z",
    "advisory" : "RHSA-2026:37136",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "tomcat-1:9.0.87-2.el8_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-07-09T00:00:00Z",
    "advisory" : "RHSA-2026:37136",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "tomcat-1:9.0.87-2.el8_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36879",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "tomcat-1:9.0.117-2.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36878",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "tomcat-1:9.0.87-2.el9_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36876",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "tomcat-1:9.0.87-2.el9_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36877",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "tomcat-1:9.0.87-4.el9_6"
  }, {
    "product_name" : "Red Hat JBoss Web Server 6.2.3",
    "release_date" : "2026-05-26T00:00:00Z",
    "advisory" : "RHSA-2026:20406",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:6.2"
  }, {
    "product_name" : "Red Hat JBoss Web Server 6.2 on RHEL 10",
    "release_date" : "2026-05-26T00:00:00Z",
    "advisory" : "RHSA-2026:20405",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
    "package" : "jws6-tomcat-0:10.1.49-13.redhat_00011.1.el10jws"
  }, {
    "product_name" : "Red Hat JBoss Web Server 6.2 on RHEL 8",
    "release_date" : "2026-05-26T00:00:00Z",
    "advisory" : "RHSA-2026:20405",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
    "package" : "jws6-tomcat-0:10.1.49-13.redhat_00011.1.el8jws"
  }, {
    "product_name" : "Red Hat JBoss Web Server 6.2 on RHEL 9",
    "release_date" : "2026-05-26T00:00:00Z",
    "advisory" : "RHSA-2026:20405",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
    "package" : "jws6-tomcat-0:10.1.49-13.redhat_00011.1.el9jws"
  }, {
    "product_name" : "Red Hat JBoss Web Server 7.0.0",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39189",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
    "package" : "tomcat"
  }, {
    "product_name" : "Red Hat JBoss Web Server 7.0 on RHEL 10",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39188",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
    "package" : "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el10jws"
  }, {
    "product_name" : "Red Hat JBoss Web Server 7.0 on RHEL 8",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39188",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
    "package" : "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el8jws"
  }, {
    "product_name" : "Red Hat JBoss Web Server 7.0 on RHEL 9",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39188",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
    "package" : "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el9jws"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "tomcat6",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Will not fix",
    "package_name" : "pki-deps:10.6/pki-servlet-engine",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "pki-servlet-engine",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat JBoss Web Server 5",
    "fix_state" : "Will not fix",
    "package_name" : "tomcat",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:5"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-29146\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-29146\nhttps://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w" ],
  "name" : "CVE-2026-29146",
  "mitigation" : {
    "value" : "This vulnerability can be mitigated by removing the affected jar file from the tomcat installation. It can be achieved by running the following command as root:\n~~~\nsystemctl stop tomcat\nrm -fv /usr/share/java/tomcat/catalina-tribes.jar\nsystemctl start tomcat\n~~~\nIt's important to notice if the Tomcat instance is configured to run with clustering, this may lead to errors when restarting the tomcat service. Red Hat's distributed Apache Tomcat should not be run with Clustering enabled, so make sure to disable such configuration before proceed with the mitigation if that's the case.",
    "lang" : "en:us"
  },
  "csaw" : false
}