CVE-2026-24734
Apache Tomcat: incomplete OCSP verification with Tomcat Native and the FFM connector
Technology
Apache Tomcat
CVSS Score
7.5 / 10.0
Affected Versions
11.0.0-M1 to 11.0.17; 10.1.0-M7 to 10.1.51; 9.0.83 to 9.0.114; Tomcat Native 1.3.0 to 1.3.4, 2.0.0 to 2.0.11; end of life but known affected: Tomcat Native 1.1.23 to 1.1.34, 1.2.0 to 1.2.39
Upstream Fix
11.0.18; 10.1.52; 9.0.115; Tomcat Native 1.3.5, 2.0.12
Published
February 17, 2026
OSSeva Coverage
Fixed upstream
Description
When an OCSP responder was used, Tomcat Native and Tomcat's FFM port of the Tomcat Native code did not complete verification or freshness checks on the OCSP response, which could allow certificate revocation to be bypassed. Rated Moderate by the Tomcat security team. Fixed in 11.0.18, 10.1.52 and 9.0.115.
Is your Apache Tomcat deployment affected?
If you're running 11.0.0-M1 to 11.0.17; 10.1.0-M7 to 10.1.51; 9.0.83 to 9.0.114; Tomcat Native 1.3.0 to 1.3.4, 2.0.0 to 2.0.11; end of life but known affected: Tomcat Native 1.1.23 to 1.1.34, 1.2.0 to 1.2.39, you need this patch. Book a discovery call to get covered.