[SECURITY] CVE-2026-59084 Apache Tomcat - EncryptInterceptor requirements not clearly documented

Mark Thomas <[email protected]>
Newsgroups gmane.comp.jakarta.tomcat.user,gmane.comp.apache.maven.announce,gmane.comp.version-control.subversion.devel
Message-ID <c9258960-d4dc-4cb3-803d-b5e125f698e6__6631.82085133798$1784016647$gmane$org@apache.org>
CVE-2026-59084 Apache Tomcat - EncryptInterceptor requirements not 
clearly documented

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.23
Apache Tomcat 10.1.0-M1 to 10.1.56
Apache Tomcat 9.0.13 to 9.0.119
Older, unsupported versions may also be affected

Description:
The requirements to securely configure the EncryptInterceptor were not 
clearly documented.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 11.0.24 or later
- Upgrade to Apache Tomcat 10.1.57 or later
- Upgrade to Apache Tomcat 9.0.120 or later

Credit:
This issue was identified by:
- NDIx

History:
2026-07-14 Original advisory

References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.