GHSA-69r9-qgr7-g2wjHighCVSS 7.5

Apache Tomcat Missing Encryption of Sensitive Data vulnerability

Published
April 9, 2026
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

🎯 Affected products6

  • maven/org.apache.tomcat:tomcat:= 11.0.20
  • maven/org.apache.tomcat:tomcat:= 10.1.53
  • maven/org.apache.tomcat:tomcat:= 9.0.116
  • maven/org.apache.tomcat:tomcat-tribes:= 11.0.20
  • maven/org.apache.tomcat:tomcat-tribes:= 10.1.53
  • maven/org.apache.tomcat:tomcat-tribes:= 9.0.116

🔗 References (12)