Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-24734

Apache Tomcat: incomplete OCSP verification with Tomcat Native and the FFM connector

Technology

Apache Tomcat

CVSS Score

7.5 / 10.0

Affected Versions

11.0.0-M1 to 11.0.17; 10.1.0-M7 to 10.1.51; 9.0.83 to 9.0.114; Tomcat Native 1.3.0 to 1.3.4, 2.0.0 to 2.0.11; end of life but known affected: Tomcat Native 1.1.23 to 1.1.34, 1.2.0 to 1.2.39

Upstream Fix

11.0.18; 10.1.52; 9.0.115; Tomcat Native 1.3.5, 2.0.12

Published

February 17, 2026

OSSeva Coverage

Fixed upstream

Description

When an OCSP responder was used, Tomcat Native and Tomcat's FFM port of the Tomcat Native code did not complete verification or freshness checks on the OCSP response, which could allow certificate revocation to be bypassed. Rated Moderate by the Tomcat security team. Fixed in 11.0.18, 10.1.52 and 9.0.115.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.0-M1 to 11.0.17; 10.1.0-M7 to 10.1.51; 9.0.83 to 9.0.114; Tomcat Native 1.3.0 to 1.3.4, 2.0.0 to 2.0.11; end of life but known affected: Tomcat Native 1.1.23 to 1.1.34, 1.2.0 to 1.2.39, you need this patch. Book a discovery call to get covered.