{"cves":["CVE-2026-29146","CVE-2026-34486"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[1:10.1.49-3]\n- Related: RHEL-168577 Remove unnecessary patch\n\n[1:10.1.49-2]\n- Resolves: RHEL-168577 Remove tomcat clustering JAR from RPM builds\n  Resolves: CVE-2026-29146\n  tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor\n  Resolves: CVE-2026-34486\n  tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass\n\n[1:10.1.36-3.el10_1.1]\n- Resolves: RHEL-150719\n  Certificate revocation bypass due to improper OCSP response validation (CVE-2026-24734)","id":"ELSA-2026-36788","ovalId":"oval:com.oracle.elsa:def:202636788","source":"oracle_linux","title":"ELSA-2026-36788:  tomcat security, bug fix, and enhancement update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-36788.html"}