¡¾·ì϶¹«¸æ¡¿Apache Tomcat EncryptInterceptorÈÆ¹ý·ì϶(CVE-2026-34486)

°ä²¼¹¦·ò 2026-04-15

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Apache Tomcat EncryptInterceptorÈÆ¹ý·ì϶

CVE   ID

CVE-2026-34486

·ì϶ÀàÐÍ

ÈÏÖ¤/ÊÚȨ»úÔìÈÆ¹ý·ì϶

·¢ÏÖ¹¦·ò

2026-4-15

·ì϶ÆÀ·Ö

7.5

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


Apache TomcatÊÇÒ»¸ö¿ªÔ´µÄJava ServletÈÝÆ÷ºÍWeb·þÎñÆ÷£¬£¬£¬£¬ £¬£¬£¬ÖØÒªÓÃÓÚÔËÐÐJavaÀûÓ÷¨Ê½£¬£¬£¬£¬ £¬£¬£¬³ö¸ñÊÇ»ùÓÚServletºÍJava Server Pages¼¼ÊõµÄÀûÓᣡ£¡£¡£¡£¡£ËüÓÉApacheÈí¼þ»ù½ð»á¿ª·¢£¬£¬£¬£¬ £¬£¬£¬¿í·ºÀûÓÃÓÚWeb¿ª·¢ºÍÆóÒµ¼¶ÀûÓ÷¨Ê½ÖУ¬£¬£¬£¬ £¬£¬£¬Ö§³ÖServlet¡¢Java Server PagesÒÔ¼°WebSocketµÈ¼¼Êõ£¬£¬£¬£¬ £¬£¬£¬ÓµÓи߻úÄÜ¡¢¿ÉÀ©´óÐԺͿ¿µÃסÐÔ¡£¡£¡£¡£¡£¡£


2026Äê4ÔÂ15ÈÕ£¬£¬£¬£¬ £¬£¬£¬8827Ì«Ñô¼¯ÍŰ²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Apache Tomcat EncryptInterceptorÈÆ¹ý·ì϶¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚ¶ÔCVE-2026-29146µÄ½¨¸´ÊµÏÖ´æÔÚÂß¼­È±µã£¬£¬£¬£¬ £¬£¬£¬µ¼ÖÂÓÃÓÚ± £» £»£»£»£»¤¼¯ÈºÍ¨Ñ¶°²È«µÄEncryptInterceptor»úÔì¿É±»Èƹý£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÊ¹Õý±¾Ó¦¼ÓÃܵÄÊý¾Ý´«Êäʧȥ± £» £»£»£»£»¤¡£¡£¡£¡£¡£¡£ÔÚÌØ¶¨Ç°ÌáÏ£¬£¬£¬£¬ £¬£¬£¬µ±TomcatÆôÓÃÁËTribes¼¯ÈºÖ°Äܲ¢ÅäÖÃEncryptInterceptorÀ¹½ØÆ÷£¬£¬£¬£¬ £¬£¬£¬ÇÒ¹¥»÷Õß¿ÉÄܽӼû¼¯ÈºÍ¨Ñ¶¶Ë¿Ú£¨Ä¬ÈÏTCP 4000£©£¬£¬£¬£¬ £¬£¬£¬Í¬Ê±Ö¸±ê·þÎñÆ÷µÄJava ClasspathÖдæÔÚ¿ÉÀûÓõķ´ÐòÁл¯GadgetÁ´Ê±£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õ߿ɻú¹Ø¶ñÒâÊý¾Ý°üÈÆ¹ý¼ÓÃÜУÑé²¢×¢Èë¶ñÒâÐòÁл¯Êý¾Ý¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶¡¢Í¨Ñ¶±»´Û¸Ä£¬£¬£¬£¬ £¬£¬£¬ÉõÖÁ½áºÏ·´ÐòÁл¯ÀûÓÃÁ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬ £¬£¬£¬½ø¶ø¶Ôϵͳ°²È«¼°Êý¾ÝºÏ¹æÐÔÔì³ÉÑϳÁÍþв¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°ÏìÁìÓò


Apache Tomcat = 11.0.20
Apache Tomcat = 10.1.53
Apache Tomcat = 9.0.116


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¹Ù·½ÒѰ䲼½¨¸´²¹¶¡£¬£¬£¬£¬ £¬£¬£¬ÒÔ½¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£¡£
Apache Tomcat >= 11.0.21
Apache Tomcat >= 10.1.54
Apache Tomcat >= 9.0.117


ÏÂÔØÁ´½Ó£ºhttps://tomcat.apache.org/


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬ £¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬£¬ £¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£¡£
? ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬£¬£¬£¬ £¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬£¬ £¬£¬£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬£¬ £¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬£¬ £¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£
? Ê¹ÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£¡£
? ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ £¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬£¬£¬£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£

? ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://nvd.nist.gov/vuln/detail/CVE-2026-34486/
https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly/