logo

Apache Tomcat Vulnerabilities Enables Bypass of EncryptInterceptor

ID: 9249a685-5798-5693-ba30-ef1b56d130e8

STIX ID: report--9249a685-5798-5693-ba30-ef1b56d130e8

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-13

Date Updated: 2026-05-05

Author: Abinaya

...
...

The Apache Software Foundation published emergency security updates for Apache Tomcat to address multiple vulnerabilities: a padding-oracle weakness in the EncryptInterceptor (CVE-2026-29146), a subsequent defective patch that permits an EncryptInterceptor bypass (CVE-2026-34486), and an OCSP certificate validation failure that can affect CLIENT_CERT authentication (CVE-2026-34500). Administrators are urged to upgrade affected branches immediately to Tomcat 11.0.21+, 10.1.54+, or 9.0.117+ to remediate decryption and authentication bypass risks across numerous 9.x, 10.x, and 11.x releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.