← Back

CVE-2026-34500

nvd nist
Published: Apr 9, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitability: 2.2 / Impact: 4.2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

Affected (16)

Products: Apache: Tomcat
1 product
Tomcat
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 10.1.22 to 10.1.54
From 11.0.1 to 11.0.21
From 9.0.92 to 9.0.117
Version 11.0.0 milestone14
Version 11.0.0 milestone15
Version 11.0.0 milestone16
Version 11.0.0 milestone17
Version 11.0.0 milestone18
Version 11.0.0 milestone19
Version 11.0.0 milestone20
Version 11.0.0 milestone21
Version 11.0.0 milestone22
Version 11.0.0 milestone23
Version 11.0.0 milestone24
Version 11.0.0 milestone25
Version 11.0.0 milestone26

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.