CVE-2026-29129: Apache Tomcat: Configured cipher preference order not preserved
(updated )
Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
References
- github.com/advisories/GHSA-69cc-cv78-qc8g
- github.com/apache/tomcat/commit/5cfa876d73f1ff5f4dc8309c4320f684cbeff74e
- github.com/apache/tomcat/commit/6db238562ec36ab1106db4d04843f8b33e7a0c06
- github.com/apache/tomcat/commit/8d69b33764dba81dce89e3a768de6093a35620ae
- lists.apache.org/thread/r4h1t6f8xhxsxfm6c2z5cprolsosho3f
- nvd.nist.gov/vuln/detail/CVE-2026-29129
- tomcat.apache.org/security-10.html
- tomcat.apache.org/security-11.html
- tomcat.apache.org/security-9.html
Code Behaviors & Features
Detect and mitigate CVE-2026-29129 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →