Database/Control plane, storage & DevOps
Apache Tomcat: Missing encryption of sensitive data introduced by the CVE-2026-29146 fix
CVSS 7.5CVE-2026-34486Control plane, storage & DevOpsKnown exploitedcurated
Impact
Missing encryption of sensitive data introduced by the CVE-2026-29146 fix
Who can reach it
Network (remote)
What to do
Control-plane: upgrade Tomcat under every Java control-plane/console service
References
Related entries
- JFrog Artifactory: internal anonymous-user token returned to unauthenticated callersCVE-2026-42018 · JFrog Artifactory (anonymous-user token disclosure)High
- Prometheus: Azure AD remote-write client secret served in plaintext from the /-/config endpointCVE-2026-42151 · Prometheus (Azure AD remote-write OAuth client_secret in /-/config)High
- Prometheus: unvalidated snappy decoded length on /api/v1/read lets a small request exhaust server memoryCVE-2026-42154 · Prometheus (/api/v1/read snappy decompression length handling)High
- OpenTelemetry JS Prometheus exporter: a malformed request URI crashes the whole Node.js processCVE-2026-44902 · OpenTelemetry JS Prometheus exporter (@opentelemetry/exporter-prometheus, also via sdk-node)High
- Suricata: unbounded NFS parser state lets crafted traffic exhaust sensor memoryCVE-2026-45766 · Suricata (NFS application-layer parser)High
- Airflow FTP provider: FTPS data channel sent in cleartext because PROT P was never issuedCVE-2026-49486 · Apache Airflow FTP provider (FTPSHook data channel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.