org.apache.tomcat:tomcat-tribes
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.tomcat:tomcat-tribespage 1 of 1
- CVE-2026-29146HIGHCVSS 7.5EG 7.52026-04-09
vulnerable: 7.0.100 ... 7.0.109 (8 versions)
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 throu…
- CVE-2026-34486HIGHCVSS 7.5EG 7.5✓ Fixed in 9.0.1172026-04-09
vulnerable: 9.0.116
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to u…
Check whether org.apache.tomcat:tomcat-tribes is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.tomcat:tomcat-tribes CVEs against the assets you own.
Start Free Scan →