CVE-2026-29129: Apache Tomcat: TLS cipher order is not preserved
Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.20 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.53 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.116
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29129?
The severity of CVE-2026-29129 is considered moderate, as it affects the TLS cipher preference order in certain versions of Apache Tomcat.
How do I fix CVE-2026-29129?
To fix CVE-2026-29129, upgrade to Apache Tomcat versions 11.0.20, 10.1.53, or 9.0.116.
Which Apache Tomcat versions are affected by CVE-2026-29129?
CVE-2026-29129 affects Apache Tomcat versions 11.0.16 through 11.0.18, 10.1.51 through 10.1.52, and 9.0.114 through 9.0.115.
What are the consequences of CVE-2026-29129?
The consequences of CVE-2026-29129 include the risk of TLS communications being compromised due to improperly ordered cipher preferences.
Is there a workaround for CVE-2026-29129?
There are no known effective workarounds for CVE-2026-29129, so upgrading to a fixed version is recommended.