{"id":"ROOT-APP-MAVEN-CVE-2026-29129","summary":"CVE-2026-29129 in org.apache.tomcat.embed:tomcat-embed-core - Patched by Root","details":"Root has patched CVE-2026-29129 in the org.apache.tomcat.embed:tomcat-embed-core package for Root:Maven. Multiple fixed versions available.","modified":"2026-09-10T07:15:05.468714512Z","published":"2026-09-10T06:50:55Z","upstream":["CVE-2026-29129"],"database_specific":{"distro_version":"","severity":"HIGH","source":"Root","distro":"maven"},"affected":[{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Root:Maven"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.1.52-aikido.3"},{"fixed":"10.1.52-aikido.2"},{"fixed":"11.0.20-aikido.15"},{"fixed":"10.1.53-aikido.9"},{"fixed":"11.0.20-aikido.12"},{"fixed":"10.1.53-aikido.10"},{"fixed":"11.0.20-aikido.16"},{"fixed":"11.0.20-aikido.13"},{"fixed":"11.0.20-aikido.14"}]}],"database_specific":{"root_patched":true,"total_fixed_versions":9,"upstream_version":"10.1.52","all_fixed_versions":["10.1.52-aikido.3","10.1.52-aikido.2","11.0.20-aikido.15","10.1.53-aikido.9","11.0.20-aikido.12","10.1.53-aikido.10","11.0.20-aikido.16","11.0.20-aikido.13","11.0.20-aikido.14"],"source":"https://api.root.io/external/osv/ROOT-APP-MAVEN-CVE-2026-29129.json","root_patch_version":"aikido.3"}},{"package":{"name":"io.root.org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Root:Maven"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.1.52-root.io.3"},{"fixed":"10.1.52-root.io.2"},{"fixed":"11.0.20-root.io.1"},{"fixed":"11.0.20-root.io.6"},{"fixed":"11.0.20-root.io.7"},{"fixed":"11.0.20-root.io.8"},{"fixed":"11.0.20-root.io.9"},{"fixed":"10.1.53-root.io.3"},{"fixed":"10.1.53-root.io.4"},{"fixed":"11.0.20-root.io.10"},{"fixed":"10.1.53-root.io.5"},{"fixed":"10.1.53-root.io.6"},{"fixed":"11.0.20-root.io.11"},{"fixed":"11.0.20-root.io.15"},{"fixed":"10.1.53-root.io.7"},{"fixed":"10.1.53-root.io.8"},{"fixed":"10.1.53-root.io.9"},{"fixed":"11.0.20-root.io.12"},{"fixed":"10.1.53-root.io.10"},{"fixed":"11.0.20-root.io.16"},{"fixed":"11.0.20-root.io.13"},{"fixed":"11.0.20-root.io.14"}]}],"database_specific":{"root_patch_version":"root.io.3","root_patched":true,"total_fixed_versions":22,"upstream_version":"10.1.52","source":"https://api.root.io/external/osv/ROOT-APP-MAVEN-CVE-2026-29129.json","all_fixed_versions":["10.1.52-root.io.3","10.1.52-root.io.2","11.0.20-root.io.1","11.0.20-root.io.6","11.0.20-root.io.7","11.0.20-root.io.8","11.0.20-root.io.9","10.1.53-root.io.3","10.1.53-root.io.4","11.0.20-root.io.10","10.1.53-root.io.5","10.1.53-root.io.6","11.0.20-root.io.11","11.0.20-root.io.15","10.1.53-root.io.7","10.1.53-root.io.8","10.1.53-root.io.9","11.0.20-root.io.12","10.1.53-root.io.10","11.0.20-root.io.16","11.0.20-root.io.13","11.0.20-root.io.14"]}}],"schema_version":"1.9.0"}