{"schema_version":"1.7.5","id":"GHSA-69cc-cv78-qc8g","published":"2026-04-09T21:31:29Z","modified":"2026-05-20T22:30:15.841678079Z","aliases":["BIT-tomcat-2026-29129","CVE-2026-29129"],"related":["CGA-pfh5-hmhh-7hcx"],"summary":"Apache Tomcat: Configured cipher preference order not preserved","details":"Configured cipher preference order not preserved vulnerability in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.\n\nUsers are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.","affected":[{"package":{"name":"org.apache.tomcat:tomcat-coyote","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-coyote"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.114"},{"fixed":"9.0.116"}]}],"versions":["9.0.115"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-69cc-cv78-qc8g/GHSA-69cc-cv78-qc8g.json"}},{"package":{"name":"org.apache.tomcat:tomcat-coyote","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-coyote"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.51"},{"fixed":"10.1.53"}]}],"versions":["10.1.52"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-69cc-cv78-qc8g/GHSA-69cc-cv78-qc8g.json"}},{"package":{"name":"org.apache.tomcat:tomcat-coyote","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-coyote"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.16"},{"fixed":"11.0.20"}]}],"versions":["11.0.18"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-69cc-cv78-qc8g/GHSA-69cc-cv78-qc8g.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.114"},{"fixed":"9.0.116"}]}],"versions":["9.0.115"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-69cc-cv78-qc8g/GHSA-69cc-cv78-qc8g.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.51"},{"fixed":"10.1.53"}]}],"versions":["10.1.52"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-69cc-cv78-qc8g/GHSA-69cc-cv78-qc8g.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.16"},{"fixed":"11.0.20"}]}],"versions":["11.0.18"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-69cc-cv78-qc8g/GHSA-69cc-cv78-qc8g.json"}},{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.114"},{"fixed":"9.0.116"}]}],"versions":["9.0.115"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-69cc-cv78-qc8g/GHSA-69cc-cv78-qc8g.json"}},{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.51"},{"fixed":"10.1.53"}]}],"versions":["10.1.52"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-69cc-cv78-qc8g/GHSA-69cc-cv78-qc8g.json"}},{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.16"},{"fixed":"11.0.20"}]}],"versions":["11.0.18"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-69cc-cv78-qc8g/GHSA-69cc-cv78-qc8g.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29129"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/5cfa876d73f1ff5f4dc8309c4320f684cbeff74e"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/6db238562ec36ab1106db4d04843f8b33e7a0c06"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/8d69b33764dba81dce89e3a768de6093a35620ae"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"https://lists.apache.org/thread/r4h1t6f8xhxsxfm6c2z5cprolsosho3f"},{"type":"WEB","url":"https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.53"},{"type":"WEB","url":"https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20"},{"type":"WEB","url":"https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.116"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/09/22"}],"database_specific":{"cwe_ids":["CWE-327"],"github_reviewed":true,"github_reviewed_at":"2026-04-10T22:07:11Z","nvd_published_at":"2026-04-09T20:16:24Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}