Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verific…
High CVSS 7.5
Summary
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
Sources
- NVD DATABASE
Original Links
- https://lists.apache.org/thread/292dlmx3fz1888v6v16221kpozq56gml Issue Tracking
- https://access.redhat.com/errata/RHSA-2026:19054
- https://access.redhat.com/errata/RHSA-2026:26323
- https://access.redhat.com/errata/RHSA-2026:5611
- https://access.redhat.com/errata/RHSA-2026:5612
- https://access.redhat.com/errata/RHSA-2026:6569
- https://access.redhat.com/errata/RHSA-2026:8334
- https://access.redhat.com/security/cve/CVE-2026-24734
- https://bugzilla.redhat.com/show_bug.cgi?id=2440426
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24734.json
- https://access.redhat.com/errata/RHSA-2026:36790
Timeline
- nvd_ingest NVD