Apache Tomcat Flaws Enable EncryptInterceptor Bypass
ID: 7677980f-a028-5c6c-b528-28517c701710
STIX ID: report--7677980f-a028-5c6c-b528-28517c701710
Feed Name: GBHackers
The Apache Software Foundation released security updates for Apache Tomcat addressing three vulnerabilities: a CBC-mode EncryptInterceptor padding oracle (CVE-2026-29146) that can allow decryption/manipulation of encrypted session data, a subsequent EncryptInterceptor bypass introduced by a flawed patch (CVE-2026-34486), and an OCSP soft-fail client certificate authentication bypass (CVE-2026-34500). Multiple Tomcat release branches and versions are impacted; administrators are urged to upgrade to 11.0.21, 10.1.54, or 9.0.117 to mitigate interception, tampering, and certificate validation bypass risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
