CVE-2026-34500: Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
CLIENTCERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.21 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.54 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.117
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34500?
CVE-2026-34500 has a medium severity rating due to its potential impact on client certificate authentication.
How do I fix CVE-2026-34500?
To fix CVE-2026-34500, upgrade Apache Tomcat to a version later than 11.0.20, 10.1.53, or 9.0.116.
What software versions are affected by CVE-2026-34500?
CVE-2026-34500 affects Apache Tomcat versions from 11.0.0-M14 to 11.0.20, from 10.1.22 to 10.1.53, and from 9.0.92 to 9.0.116.
What issue does CVE-2026-34500 describe?
CVE-2026-34500 describes a flaw in which OCSP checks may soft-fail with FFM even when soft-fail is disabled during CLIENT_CERT authentication.
Are there any workarounds for CVE-2026-34500?
No specific workarounds are recommended for CVE-2026-34500; upgrading to a patched version is advised.