Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2886 articles · 109696 vulns · 38/41 feeds (7d)
← Back to list
—
CVE-2026-29145PATCHED
apache software foundation · apache tomcat

Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled

Description

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.

Affected Products

VendorProductVersions
apache software foundationapache tomcat11.0.0-M1, 10.1.0-M7, 9.0.83, 1.1.23, 1.2.0, 1.3.0, 2.0.0

References

  • https://lists.apache.org/thread/yz5fxmhd2j43wgqykssdo7kltws57jfz(vendor-advisory)

Related News (2 articles)

Tier C
oss-security7h ago
CVE-2026-29145: Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
→ No new info (linked only)
Tier C
VulDB9h ago
CVE-2026-29145 | Apache Tomcat up to 8.5.99/9.0.115/10.1.52/11.0.18 CLIENT_CERT Authentication improper authentication
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
0
PublishedApr 9, 2026
Last enriched9h agov2
Tags
CVE-2026-29145
Trending Score31
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-35554
Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
Trending: 36
MEDIUMCVE-2026-34500
Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Trending: 34
IMPORTANTCVE-2026-29146
Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
Trending: 32
NONECVE-2026-24880
Apache Tomcat: Request smuggling via invalid chunk extension
Trending: 31
NONECVE-2026-25854
Apache Tomcat: Occasionally open redirect
Trending: 31

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 9, 2026
Discovered by ZDM
Apr 9, 2026
Updated: severity, cweIds, tags
Apr 9, 2026
Patch Available
Apr 9, 2026

Version History

v2
Last enriched 9h ago
v2Tier C9h ago

Updated severity to CRITICAL, added CWE-287, and included CVE-2026-29145 as a new tag.

severitycweIdstags
via VulDB
v110h ago

Initial creation