Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass
Summary
| CVE | CVE-2026-24734 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-02-17 19:21:56 UTC |
| Updated | 2026-07-15 14:17:21 UTC |
| Description | Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Problem Types: CWE-20 | NVD-CWE-noinfo | CWE-295 | CWE-20 CWE-20 Improper Input Validation | CWE-295 Improper Certificate Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| 3.1 | ADP | DECLARED | 7.4 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | ADP | CVSS | 7.4 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.4 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 7.4 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Tomcat Native | affected 1.1.23 1.1.34 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat Native | affected 1.2.0 1.2.39 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat Native | affected 1.3.0 1.3.4 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat Native | affected 2.0.0 2.0.11 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 11.0.0-M1 11.0.17 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 10.1.0-M7 10.1.51 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 9.0.83 9.0.114 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | unaffected 8.5.100 semver | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | unaffected 1:10.1.49-1.el10_2.1 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | unaffected 1:9.0.117-1.el9_8 * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6.2.1 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6.2 On RHEL 10 | unaffected 0:10.1.49-9.redhat_00007.1.el10jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6.2 On RHEL 10 | unaffected 0:1.3.6-1.redhat_1.el10jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6.2 On RHEL 8 | unaffected 0:10.1.49-9.redhat_00007.1.el8jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6.2 On RHEL 8 | unaffected 0:1.3.6-1.redhat_1.el8jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6.2 On RHEL 9 | unaffected 0:10.1.49-9.redhat_00007.1.el9jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6.2 On RHEL 9 | unaffected 0:1.3.6-1.redhat_1.el9jws * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 11.0.21-0.1.hum1 * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 10.1.54-1.hum1 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 6 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 7 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 5 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:5611 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36790 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24734.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:19054 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:8334 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:5612 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| lists.apache.org/thread/292dlmx3fz1888v6v16221kpozq56gml | [email protected] | lists.apache.org | Issue Tracking, Mailing List, Vendor Advisory |
| access.redhat.com/errata/RHSA-2026:26323 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-24734 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:6569 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Joshua Rogers (@MegaManSec) (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-02-17T20:03:45.051Z | Reported to Red Hat. |
| ADP | 2026-02-17T18:53:12.228Z | Made public. |
Solutions
ADP: RHSA-2026:5611: Red Hat JBoss Web Server 6.2 on RHEL 10, Red Hat JBoss Web Server 6.2 on RHEL 8, Red Hat JBoss Web Server 6.2 on RHEL 9
ADP: RHSA-2026:19054: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:36790: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:26323: Red Hat Enterprise Linux AppStream (v. 9)
ADP: RHSA-2026:8334: Red Hat Hardened Images
ADP: RHSA-2026:6569: Red Hat Hardened Images
ADP: RHSA-2026:5612: Red Hat JBoss Web Server 6.2.1