Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass (CVE-2026-24734)
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0 through 11.0.17, from 10.1.0 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.
AI Analysis
Technical Summary
This security advisory addresses CVE-2026-24734, a vulnerability in Apache Tomcat where improper validation of OCSP (Online Certificate Status Protocol) responses can lead to certificate revocation bypass. This means that Tomcat may incorrectly accept revoked certificates as valid, potentially undermining the security of TLS connections. The issue affects Red Hat JBoss Web Server components bundled with Red Hat Enterprise Linux versions 9 and 10. Red Hat has released updated Tomcat packages that fix this vulnerability. The advisory references multiple Red Hat errata and provides detailed package versions and SHA-256 checksums for the fixed releases.
Potential Impact
The vulnerability allows an attacker to bypass certificate revocation checks due to improper OCSP response validation in Apache Tomcat. This could result in acceptance of revoked certificates, potentially enabling man-in-the-middle attacks or other TLS-related security bypasses. The severity is rated as high by Red Hat Product Security. There are no known exploits in the wild at this time.
Mitigation Recommendations
Official patches fixing this vulnerability are available from Red Hat for affected versions of Tomcat in Red Hat Enterprise Linux 9 and 10. Users should apply the updates as described in the Red Hat advisories (RHSA-2026:19054 and RHSA-2026:26323) and the referenced article https://access.redhat.com/articles/11258. No additional mitigation is required beyond applying these official fixes.
Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass (CVE-2026-24734)
Description
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0 through 11.0.17, from 10.1.0 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.
Affected software
pkg:bitnami/tomcatRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This security advisory addresses CVE-2026-24734, a vulnerability in Apache Tomcat where improper validation of OCSP (Online Certificate Status Protocol) responses can lead to certificate revocation bypass. This means that Tomcat may incorrectly accept revoked certificates as valid, potentially undermining the security of TLS connections. The issue affects Red Hat JBoss Web Server components bundled with Red Hat Enterprise Linux versions 9 and 10. Red Hat has released updated Tomcat packages that fix this vulnerability. The advisory references multiple Red Hat errata and provides detailed package versions and SHA-256 checksums for the fixed releases.
Potential Impact
The vulnerability allows an attacker to bypass certificate revocation checks due to improper OCSP response validation in Apache Tomcat. This could result in acceptance of revoked certificates, potentially enabling man-in-the-middle attacks or other TLS-related security bypasses. The severity is rated as high by Red Hat Product Security. There are no known exploits in the wild at this time.
Mitigation Recommendations
Official patches fixing this vulnerability are available from Red Hat for affected versions of Tomcat in Red Hat Enterprise Linux 9 and 10. Users should apply the updates as described in the Red Hat advisories (RHSA-2026:19054 and RHSA-2026:26323) and the referenced article https://access.redhat.com/articles/11258. No additional mitigation is required beyond applying these official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:19054
- Cve Count
- 1
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a2bea10e617e2d8345887c3
Added to database: 06/12/2026, 11:14:24 UTC
Last enriched: 08/08/2026, 16:55:43 UTC
Last updated: 09/21/2026, 10:01:31 UTC
Views: 211
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.