|
1 | 1 | { |
2 | 2 | "schema_version": "1.4.0", |
3 | 3 | "id": "GHSA-h468-7pvh-8vr8", |
4 | | - "modified": "2026-04-10T21:32:09Z", |
| 4 | + "modified": "2026-04-10T21:32:12Z", |
5 | 5 | "published": "2026-04-09T21:31:29Z", |
6 | 6 | "aliases": [ |
7 | 7 | "CVE-2026-29146" |
8 | 8 | ], |
9 | 9 | "summary": "Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor", |
10 | 10 | "details": "Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.\n\nUsers are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.", |
11 | 11 | "severity": [ |
12 | | - { |
13 | | - "type": "CVSS_V3", |
14 | | - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" |
15 | | - }, |
16 | 12 | { |
17 | 13 | "type": "CVSS_V4", |
18 | 14 | "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" |
|
22 | 18 | { |
23 | 19 | "package": { |
24 | 20 | "ecosystem": "Maven", |
25 | | - "name": "org.apache.tomcat:tomcat-catalina" |
| 21 | + "name": "org.apache.tomcat:tomcat-tribes" |
26 | 22 | }, |
27 | 23 | "ranges": [ |
28 | 24 | { |
|
41 | 37 | { |
42 | 38 | "package": { |
43 | 39 | "ecosystem": "Maven", |
44 | | - "name": "org.apache.tomcat:tomcat-catalina" |
| 40 | + "name": "org.apache.tomcat:tomcat-tribes" |
45 | 41 | }, |
46 | 42 | "ranges": [ |
47 | 43 | { |
|
60 | 56 | { |
61 | 57 | "package": { |
62 | 58 | "ecosystem": "Maven", |
63 | | - "name": "org.apache.tomcat:tomcat-catalina" |
| 59 | + "name": "org.apache.tomcat:tomcat-tribes" |
64 | 60 | }, |
65 | 61 | "ranges": [ |
66 | 62 | { |
|
136 | 132 | { |
137 | 133 | "package": { |
138 | 134 | "ecosystem": "Maven", |
139 | | - "name": "org.apache.tomcat.embed:tomcat-embed-core" |
| 135 | + "name": "org.apache.tomcat:tomcat" |
140 | 136 | }, |
141 | 137 | "ranges": [ |
142 | 138 | { |
143 | 139 | "type": "ECOSYSTEM", |
144 | 140 | "events": [ |
145 | 141 | { |
146 | | - "introduced": "9.0.13" |
| 142 | + "introduced": "8.5.38" |
147 | 143 | }, |
148 | 144 | { |
149 | | - "fixed": "9.0.116" |
| 145 | + "last_affected": "8.5.100" |
150 | 146 | } |
151 | 147 | ] |
152 | 148 | } |
|
155 | 151 | { |
156 | 152 | "package": { |
157 | 153 | "ecosystem": "Maven", |
158 | | - "name": "org.apache.tomcat.embed:tomcat-embed-core" |
| 154 | + "name": "org.apache.tomcat:tomcat" |
159 | 155 | }, |
160 | 156 | "ranges": [ |
161 | 157 | { |
162 | 158 | "type": "ECOSYSTEM", |
163 | 159 | "events": [ |
164 | 160 | { |
165 | | - "introduced": "10.1.50" |
| 161 | + "introduced": "7.0.100" |
166 | 162 | }, |
167 | 163 | { |
168 | | - "fixed": "10.1.53" |
| 164 | + "last_affected": "7.0.109" |
169 | 165 | } |
170 | 166 | ] |
171 | 167 | } |
|
174 | 170 | { |
175 | 171 | "package": { |
176 | 172 | "ecosystem": "Maven", |
177 | | - "name": "org.apache.tomcat.embed:tomcat-embed-core" |
| 173 | + "name": "org.apache.tomcat:tomcat-tribes" |
178 | 174 | }, |
179 | 175 | "ranges": [ |
180 | 176 | { |
181 | 177 | "type": "ECOSYSTEM", |
182 | 178 | "events": [ |
183 | 179 | { |
184 | | - "introduced": "11.0.0-M1" |
| 180 | + "introduced": "8.5.38" |
185 | 181 | }, |
186 | 182 | { |
187 | | - "fixed": "11.0.19" |
| 183 | + "last_affected": "8.5.100" |
| 184 | + } |
| 185 | + ] |
| 186 | + } |
| 187 | + ] |
| 188 | + }, |
| 189 | + { |
| 190 | + "package": { |
| 191 | + "ecosystem": "Maven", |
| 192 | + "name": "org.apache.tomcat:tomcat-tribes" |
| 193 | + }, |
| 194 | + "ranges": [ |
| 195 | + { |
| 196 | + "type": "ECOSYSTEM", |
| 197 | + "events": [ |
| 198 | + { |
| 199 | + "introduced": "7.0.100" |
| 200 | + }, |
| 201 | + { |
| 202 | + "last_affected": "7.0.109" |
188 | 203 | } |
189 | 204 | ] |
190 | 205 | } |
|
204 | 219 | "type": "WEB", |
205 | 220 | "url": "https://lists.apache.org/thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w" |
206 | 221 | }, |
| 222 | + { |
| 223 | + "type": "WEB", |
| 224 | + "url": "https://www.herodevs.com/vulnerability-directory/cve-2026-29146" |
| 225 | + }, |
207 | 226 | { |
208 | 227 | "type": "WEB", |
209 | 228 | "url": "http://www.openwall.com/lists/oss-security/2026/04/09/24" |
|
0 commit comments