logo

Apache Tomcat Flaws Enable EncryptInterceptor Bypass

ID: 7677980f-a028-5c6c-b528-28517c701710

STIX ID: report--7677980f-a028-5c6c-b528-28517c701710

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-13

Date Updated: 2026-07-21

Author: Divya

...
...

The Apache Software Foundation released security updates for Apache Tomcat addressing three vulnerabilities: a CBC-mode EncryptInterceptor padding oracle (CVE-2026-29146) that can allow decryption/manipulation of encrypted session data, a subsequent EncryptInterceptor bypass introduced by a flawed patch (CVE-2026-34486), and an OCSP soft-fail client certificate authentication bypass (CVE-2026-34500). Multiple Tomcat release branches and versions are impacted; administrators are urged to upgrade to 11.0.21, 10.1.54, or 9.0.117 to mitigate interception, tampering, and certificate validation bypass risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.