RHSA-2026:38505HighCVSS 7.5

Red Hat Security Advisory: tomcat security, bug fix, and enhancement update

Published
July 13, 2026
Last Modified
July 14, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-29146 — Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor CVE-2026-34486 — Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass

🔗 References (6)