CVE-2026-29129
published 2026-04-09CVE-2026-29129: Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.26%
17.4th percentile
Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 10.1.51 < 10.1.53 | 10.1.53 |
| apache | tomcat | >= 11.0.16 < 11.0.20 | 11.0.20 |
| apache | tomcat | >= 9.0.114 < 9.0.116 | 9.0.116 |
| apache_software_foundation | apache_tomcat | 10.1.51 – 10.1.52 | — |
| apache_software_foundation | apache_tomcat | 11.0.16 – 11.0.18 | — |
| apache_software_foundation | apache_tomcat | 9.0.114 – 9.0.115 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Tomcat up to 9.0.115/10.1.52/11.0.18 Cipher Preference Order information disclosure
vuldb·2026-04-09·CVSS 7.5
CVE-2026-29129 [HIGH] Apache Tomcat up to 9.0.115/10.1.52/11.0.18 Cipher Preference Order information disclosure
A vulnerability identified as problematic has been detected in Apache Tomcat up to 9.0.115/10.1.52/11.0.18. The affected element is an unknown function of the component Cipher Preference Order. This manipulation causes information disclosure.
The identification of this vulnerability is CVE-2026-29129. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
GHSA-69cc-cv78-qc8g: Configured cipher preference order not preserved vulnerability in Apache Tomcat
ghsa_unreviewed·2026-04-09
CVE-2026-29129 GHSA-69cc-cv78-qc8g: Configured cipher preference order not preserved vulnerability in Apache Tomcat
Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
GHSA
Apache Tomcat: Configured cipher preference order not preserved
ghsa·2026-04-09
CVE-2026-29129 [HIGH] CWE-327 Apache Tomcat: Configured cipher preference order not preserved
Apache Tomcat: Configured cipher preference order not preserved
Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
Red Hat
Apache Tomcat: Apache Tomcat: Configured cipher preference order not preserved
vendor_redhat·2026-04-09·CVSS 7.5
CVE-2026-29129 [HIGH] CWE-15 Apache Tomcat: Apache Tomcat: Configured cipher preference order not preserved
Apache Tomcat: Apache Tomcat: Configured cipher preference order not preserved
Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
A flaw was found in Apache Tomcat. This vulnerability occurs when the configured cipher preference order is not preserved. This could allow an attacker to bypass intended security configurations, potentially leading to a weakened security posture or information disclosure.
Statement: Low impact. A flaw in Apache Tomcat allows the configured cipher preference order to be bypassed. This could lead to a server using a
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-29129 tomcat: Apache Tomcat: Configured cipher preference order not preserved [fedora-all]
bugzilla·2026-04-10·CVSS 7.5
CVE-2026-29129 [HIGH] CVE-2026-29129 tomcat: Apache Tomcat: Configured cipher preference order not preserved [fedora-all]
CVE-2026-29129 tomcat: Apache Tomcat: Configured cipher preference order not preserved [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-29129 Apache Tomcat: Apache Tomcat: Configured cipher preference order not preserved
bugzilla·2026-04-09·CVSS 7.5
CVE-2026-29129 [HIGH] CVE-2026-29129 Apache Tomcat: Apache Tomcat: Configured cipher preference order not preserved
CVE-2026-29129 Apache Tomcat: Apache Tomcat: Configured cipher preference order not preserved
Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
2026-04-09
Published