
Fun story: #Apache patched a Tomcat padding oracle and shipped a worse bug doing it. #CVE-2026-29146: EncryptInterceptor defaults to AES/CBC/PKCS5, a padding oracle. No key needed, forge cluster messages on the Tribes receiver (TCP/4000, no peer auth) and you're a trusted node. > The patch moved super.messageReceived() out of the try. Then? Decrypt fails, Tomcat deserializes your bytes anyway: badab00m! That's CVE-2026-34486, pre-auth RCE! Patch to be safe, pwn for the lulz 😎 > Fix: 9.0.117 / 10.1.54 / 11.0.21. Or GCM/NoPadding and keep 4000 off untrusted wires. Whole story & details by @cyberkendra : https://www.cyberkendra.com/2026/04/apache-tomcats-security-fix-opened-door.html PoC from @striga_ai : http://github.com/striga-ai/CVE-2026-34486
Post summary
Apache Tomcat was found to have a padding oracle (CVE-2026-29146) and a pre‑auth RCE (CVE-2026-34486) with available patches, a PoC in GitHub, but no evidence of live exploitation is reported.









