CVE 6.5 MEDIUM

Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled_CVE-2026-34500

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

Description

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

Basic Information

ID CVE-2026-34500
Source apache
Published Apr 9, 2026 at 19:36
Modified Apr 10, 2026 at 14:22

Affected Product

Vendor Apache Software Foundation
Product Apache Tomcat
Version 11.0.0-M14
Affected Versions Apache Software Foundation Apache Tomcat 11.0.0-M14
Apache Software Foundation Apache Tomcat 10.1.22
Apache Software Foundation Apache Tomcat 9.0.92

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.