Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
Summary
| CVE | CVE-2026-29145 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-09 20:16:24 UTC |
| Updated | 2026-04-10 19:16:21 UTC |
| Description | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue. |
Risk And Classification
Primary CVSS: v3.1 9.1 CRITICAL from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Problem Types: CWE-287 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled | CWE-287 CWE-287 Improper Authentication
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Tomcat | affected 11.0.0-M1 11.0.18 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 10.1.0-M7 10.1.52 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 9.0.83 9.0.115 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | unaffected 8.5.100 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat Native | affected 1.1.23 1.1.34 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat Native | affected 1.2.0 1.2.39 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat Native | affected 1.3.0 1.3.6 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat Native | affected 2.0.0 2.0.13 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.openwall.com/lists/oss-security/2026/04/09/23 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| lists.apache.org/thread/yz5fxmhd2j43wgqykssdo7kltws57jfz | [email protected] | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: gregk4sec (https://github.com/gregk4sec) (en)
There are currently no legacy QID mappings associated with this CVE.