← Back

CVE-2026-29145

nvd nist
Published: Apr 9, 2026Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.

Affected (20)

2 products
Tomcat
Tomcat Native
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 10.1.1 to 10.1.53
From 11.0.0 to 11.0.20
From 9.0.83 to 9.0.116
Version 10.1.0
Version 10.1.0 milestone10
Version 10.1.0 milestone11
Version 10.1.0 milestone12
Version 10.1.0 milestone13
Version 10.1.0 milestone14
Version 10.1.0 milestone15
Version 10.1.0 milestone16
Version 10.1.0 milestone17
Version 10.1.0 milestone18
Version 10.1.0 milestone19
Version 10.1.0 milestone20
Version 10.1.0 milestone7
Version 10.1.0 milestone8
Version 10.1.0 milestone9
Apache
From 1.1.23 to 1.3.7
From 2.0.0 to 2.0.14

References (2)

Source: security@apache.org
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.