[SECURITY] CVE-2026-34500 Apache Tomcat - OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas <[email protected]> Thu, 9 Apr 2026 20:03:36 +0100
| Newsgroups | gmane.comp.version-control.subversion.devel,gmane.comp.jakarta.tomcat.user,gmane.comp.apache.maven.announce |
|---|---|
| Message-ID | <c36d3af3-d446-4bd2-a9ad-6ca6bc4db202__15750.14292482$1775763037$gmane$org@apache.org> |
CVE-2026-34500 Apache Tomcat - OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M14 to 11.0.20 Apache Tomcat 10.1.22 to 10.1.53 Apache Tomcat 9.0.92 to 9.0.116 Description: CLIENT_CERT authentication did not fail as expected for some scenarios when soft fail was disabled and FFM was used Mitigation: Users of the affected versions should apply one of the following mitigations: - Upgrade to Apache Tomcat 11.0.21 or later - Upgrade to Apache Tomcat 10.1.54 or later - Upgrade to Apache Tomcat 9.0.117 or later Credit: This issue was identified by Haruki Oyama (Waseda University) History: 2026-04-09 Original advisory References: [1] https://tomcat.apache.org/security-11.html [2] https://tomcat.apache.org/security-10.html [3] https://tomcat.apache.org/security-9.html