PT-2026-20317 · Apache · Apache Tomcat+1
Joshua Rogers
·
Published
2026-01-01
·
Updated
2026-03-30
·
CVE-2026-24734
CVSS v3.1
7.5
High
| AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat Native versions 1.3.0 through 1.3.4
Apache Tomcat Native versions 2.0.0 through 2.0.11
Apache Tomcat versions 11.0.0-M1 through 11.0.17
Apache Tomcat versions 10.1.0-M7 through 10.1.51
Apache Tomcat versions 9.0.83 through 9.0.114
Apache Tomcat Native versions 1.1.23 through 1.1.34
Apache Tomcat Native versions 1.2.0 through 1.2.39
Description
An improper input validation issue exists in Apache Tomcat Native and Apache Tomcat when using an OCSP responder. The software did not complete verification or freshness checks on the OCSP response, potentially allowing certificate revocation to be bypassed. The issue was reported on November 2, 2025, and made public on February 17, 2026.
Recommendations
Apache Tomcat Native versions 1.3.5 or later should be used.
Apache Tomcat Native versions 2.0.12 or later should be used.
Apache Tomcat versions 11.0.18 or later should be used.
Apache Tomcat versions 10.1.52 or later should be used.
Apache Tomcat versions 9.0.115 or later should be used.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat
Apache Tomcat Native