FixVibe

// discovery / spotlight

Apache Tomcat EncryptInterceptor Padding-Oracle Advisory

Affected Tomcat releases plus CBC cluster-encryption configuration warrant an immediate runtime upgrade.

Il gancio

Tomcat clustering is often deployed through a mix of application dependencies, external servlet containers, and environment-specific `server.xml` files. CVE-2026-29146 depends on both an affected runtime and EncryptInterceptor configuration, so FixVibe reports the correlated repository evidence without presenting it as confirmed production exposure.

Come funziona

The repo check evaluates both the declared Tomcat runtime and the relevant cluster-encryption posture. A reported finding contains actionable dependency and configuration locations, and encryption-key material is never retained.

Il raggio d'azione

If the matched runtime and cluster configuration are deployed and an attacker can reach or observe the relevant inter-node channel, the encryption behavior may expose sensitive cluster traffic under the advisory conditions. Repository correlation makes remediation actionable, but it does not prove the configuration is deployed, the cluster channel is reachable, or any plaintext was recovered.

// cosa controlla fixvibe

Cosa controlla FixVibe

FixVibe maps externally visible application surfaces with passive signals and safe metadata checks. Reports summarize the exposed surface and remediation priorities. For check-specific questions about exact detection heuristics, active payload details, or source-code rule patterns, contact support@fixvibe.app.

Difese a prova di bomba

Upgrade to the latest supported Tomcat release, no lower than 9.0.117, 10.1.54, or 11.0.21 for the active line; migrate Tomcat 7, 8.5, and 10.0 deployments to a supported line. Align all cluster nodes and Tomcat modules, rebuild and redeploy the actual runtime, and rotate any literal cluster encryption key that entered source control before loading its replacement from an approved runtime secret source.

// run it on your own app

Continua a spedire mentre FixVibe vigila per te.

FixVibe mette sotto pressione la superficie pubblica della tua app come farebbe un attaccante — senza agent, senza installazione, senza carta. Continuiamo a studiare nuovi pattern di vulnerabilità e li trasformiamo in controlli pratici e fix pronti da incollare in Cursor, Claude e Copilot.

Discovery
146
test eseguiti in questa categoria
modules
27
controlli dedicati a discovery
ogni scansione
540+
test su tutte le categorie
  • Gratis — senza carta di credito, senza installazione, senza ping su Slack
  • Incolla un URL — pensiamo noi a crawl, sonde e report
  • Risultati classificati in base alla gravità, deduplicati solo per segnalare
  • AI-ready prompts where code applies, plus operator steps for DNS/provider fixes
Esegui una scansione gratuita

// latest checks · practical fixes · ship with confidence

Apache Tomcat EncryptInterceptor Padding-Oracle Advisory — Vulnerabilità in primo piano | FixVibe · FixVibe