Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-29145

Apache Tomcat: OCSP checks sometimes soft-fail when soft fail is disabled

Technology

Apache Tomcat

CVSS Score

9.1 / 10.0

Affected Versions

11.0.0-M1 to 11.0.18; 10.1.0-M7 to 10.1.52; 9.0.83 to 9.0.115; Tomcat Native 1.1.23 to 1.1.34, 1.2.0 to 1.2.39, 1.3.0 to 1.3.6, 2.0.0 to 2.0.13

Upstream Fix

11.0.20; 10.1.53; 9.0.116; Tomcat Native 1.3.7, 2.0.14

Published

April 9, 2026

OSSeva Coverage

Fixed upstream

Description

CLIENT_CERT authentication did not fail OCSP checks as expected in some scenarios when soft fail was disabled, so a revoked client certificate could be accepted. Rated Moderate by the Tomcat security team; CISA-ADP scores it 9.1. Fixed in 11.0.20, 10.1.53 and 9.0.116, and in Tomcat Native 1.3.7 and 2.0.14. CVE-2026-34500 and CVE-2026-86248 later fixed related cases with the FFM connector.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.0-M1 to 11.0.18; 10.1.0-M7 to 10.1.52; 9.0.83 to 9.0.115; Tomcat Native 1.1.23 to 1.1.34, 1.2.0 to 1.2.39, 1.3.0 to 1.3.6, 2.0.0 to 2.0.13, you need this patch. Book a discovery call to get covered.