Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Update org.apache.tomcat:tomcat to 9.0.117; org.apache.tomcat:tomcat to 11.0.21; org.apache.tomcat:tomcat to 10.1.54; org.apache.tomcat:tomcat-tribes to 11.0.21; org.apache.tomcat:tomcat-tribes to 10.1.54; org.apache.tomcat:tomcat-tribes to 9.0.117 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Tomcat Missing Encryption of Sensitive Data vulnerability affects org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat-tribes (maven), org.apache.tomcat:tomcat-tribes (maven), org.apache.tomcat:tomcat-tribes (maven). Severity is high. Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Update org.apache.tomcat:tomcat to 9.0.117; org.apache.tomcat:tomcat to 11.0.21; org.apache.tomcat:tomcat to 10.1.54; org.apache.tomcat:tomcat-tribes to 11.0.21; org.apache.tomcat:tomcat-tribes to 10.1.54; org.apache.tomcat:tomcat-tribes to 9.0.117 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Tomcat Missing Encryption of Sensitive Data vulnerability affects org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat-tribes (maven), org.apache.tomcat:tomcat-tribes (maven), org.apache.tomcat:tomcat-tribes (maven). Severity is high. Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.tomcat:tomcatmaven |
|---|
| =9.0.116 |
| 9.0.117 |
| org.apache.tomcat:tomcatmaven | =11.0.20 | 11.0.21 |
|---|
| org.apache.tomcat:tomcatmaven | =10.1.53 | 10.1.54 |
|---|
| org.apache.tomcat:tomcat-tribesmaven | =11.0.20 | 11.0.21 |
|---|
| org.apache.tomcat:tomcat-tribesmaven | =10.1.53 | 10.1.54 |
|---|
| org.apache.tomcat:tomcat-tribesmaven | =9.0.116 | 9.0.117 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| org.apache.tomcat:tomcatmaven |
|---|
| =9.0.116 |
| 9.0.117 |
| org.apache.tomcat:tomcatmaven | =11.0.20 | 11.0.21 |
|---|
| org.apache.tomcat:tomcatmaven | =10.1.53 | 10.1.54 |
|---|
| org.apache.tomcat:tomcat-tribesmaven | =11.0.20 | 11.0.21 |
|---|
| org.apache.tomcat:tomcat-tribesmaven | =10.1.53 | 10.1.54 |
|---|
| org.apache.tomcat:tomcat-tribesmaven | =9.0.116 | 9.0.117 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard