CVE-2026-29145: Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
CLIENTCERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13.
Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcat Nativeto a version that resolves this vulnerability.Fixed in 1.3.7 - Upgrade
Upgrade
Apache Tomcat Nativeto a version that resolves this vulnerability.Fixed in 2.0.14 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.20 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.53 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.116 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-29145
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29145?
CVE-2026-29145 is classified as a moderate severity vulnerability.
How do I fix CVE-2026-29145?
To fix CVE-2026-29145, update Apache Tomcat or Apache Tomcat Native to the latest version that has addressed this vulnerability.
What versions are affected by CVE-2026-29145?
CVE-2026-29145 affects Apache Tomcat versions 11.0.0-M1 to 11.0.18, 10.1.0-M7 to 10.1.52, and 9.0.83 to 9.0.115, along with specific Apache Tomcat Native versions.
What does CVE-2026-29145 impact?
CVE-2026-29145 impacts the OCSP checks in Apache Tomcat and Apache Tomcat Native, causing unexpected behavior in CLIENT_CERT authentication.
Is user data at risk due to CVE-2026-29145?
Yes, due to the potential authentication failure scenarios, user data could be at risk if this vulnerability is exploited.