CVE-2026-29145
Apache Tomcat: OCSP checks sometimes soft-fail when soft fail is disabled
Technology
Apache Tomcat
CVSS Score
9.1 / 10.0
Affected Versions
11.0.0-M1 to 11.0.18; 10.1.0-M7 to 10.1.52; 9.0.83 to 9.0.115; Tomcat Native 1.1.23 to 1.1.34, 1.2.0 to 1.2.39, 1.3.0 to 1.3.6, 2.0.0 to 2.0.13
Upstream Fix
11.0.20; 10.1.53; 9.0.116; Tomcat Native 1.3.7, 2.0.14
Published
April 9, 2026
OSSeva Coverage
Fixed upstream
Description
CLIENT_CERT authentication did not fail OCSP checks as expected in some scenarios when soft fail was disabled, so a revoked client certificate could be accepted. Rated Moderate by the Tomcat security team; CISA-ADP scores it 9.1. Fixed in 11.0.20, 10.1.53 and 9.0.116, and in Tomcat Native 1.3.7 and 2.0.14. CVE-2026-34500 and CVE-2026-86248 later fixed related cases with the FFM connector.
Is your Apache Tomcat deployment affected?
If you're running 11.0.0-M1 to 11.0.18; 10.1.0-M7 to 10.1.52; 9.0.83 to 9.0.115; Tomcat Native 1.1.23 to 1.1.34, 1.2.0 to 1.2.39, 1.3.0 to 1.3.6, 2.0.0 to 2.0.13, you need this patch. Book a discovery call to get covered.