PT-2026-20317 · Apache · Apache Tomcat+1

Joshua Rogers

·

Published

2026-01-01

·

Updated

2026-03-30

·

CVE-2026-24734

CVSS v3.1

7.5

High

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat Native versions 1.3.0 through 1.3.4 Apache Tomcat Native versions 2.0.0 through 2.0.11 Apache Tomcat versions 11.0.0-M1 through 11.0.17 Apache Tomcat versions 10.1.0-M7 through 10.1.51 Apache Tomcat versions 9.0.83 through 9.0.114 Apache Tomcat Native versions 1.1.23 through 1.1.34 Apache Tomcat Native versions 1.2.0 through 1.2.39
Description An improper input validation issue exists in Apache Tomcat Native and Apache Tomcat when using an OCSP responder. The software did not complete verification or freshness checks on the OCSP response, potentially allowing certificate revocation to be bypassed. The issue was reported on November 2, 2025, and made public on February 17, 2026.
Recommendations Apache Tomcat Native versions 1.3.5 or later should be used. Apache Tomcat Native versions 2.0.12 or later should be used. Apache Tomcat versions 11.0.18 or later should be used. Apache Tomcat versions 10.1.52 or later should be used. Apache Tomcat versions 9.0.115 or later should be used.

Fix

RCE

Weakness Enumeration

Related Identifiers

BIT-TOMCAT-2026-24734
CVE-2026-24734
GHSA-MGP5-RV84-W37Q
MGASA-2026-0056
OESA-2026-1651
OPENSUSE-SU-2026:10305-1
OPENSUSE-SU-2026:10306-1
OPENSUSE-SU-2026:10307-1
OPENSUSE-SU-2026:20350-1
OPENSUSE-SU-2026:20414-1
OPENSUSE-SU-2026:20444-1
SUSE-SU-2026:0877-1
SUSE-SU-2026:0890-1
SUSE-SU-2026:0932-1
SUSE-SU-2026:20926-1

Affected Products

Apache Tomcat
Apache Tomcat Native