Skip to main content
EPSS 0.5%top 57%

Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass (CVE-2026-24734)

0
High
Published: 02/20/2026 (02/20/2026, 09:53:00 UTC)
Source: GCVE Database
Product: tomcat

Description

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0 through 11.0.17, from 10.1.0 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.

Affected software

Bitnamimore threats →ghsa
tomcat
pkg:bitnami/tomcat
Affected versions
>=9.0.83 <9.0.115>=10.1.0 <10.1.52>=11.0.0 <11.0.18

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/08/2026, 16:55:43 UTC

Technical Analysis

This security advisory addresses CVE-2026-24734, a vulnerability in Apache Tomcat where improper validation of OCSP (Online Certificate Status Protocol) responses can lead to certificate revocation bypass. This means that Tomcat may incorrectly accept revoked certificates as valid, potentially undermining the security of TLS connections. The issue affects Red Hat JBoss Web Server components bundled with Red Hat Enterprise Linux versions 9 and 10. Red Hat has released updated Tomcat packages that fix this vulnerability. The advisory references multiple Red Hat errata and provides detailed package versions and SHA-256 checksums for the fixed releases.

Potential Impact

The vulnerability allows an attacker to bypass certificate revocation checks due to improper OCSP response validation in Apache Tomcat. This could result in acceptance of revoked certificates, potentially enabling man-in-the-middle attacks or other TLS-related security bypasses. The severity is rated as high by Red Hat Product Security. There are no known exploits in the wild at this time.

Mitigation Recommendations

Official patches fixing this vulnerability are available from Red Hat for affected versions of Tomcat in Red Hat Enterprise Linux 9 and 10. Users should apply the updates as described in the Red Hat advisories (RHSA-2026:19054 and RHSA-2026:26323) and the referenced article https://access.redhat.com/articles/11258. No additional mitigation is required beyond applying these official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:19054
Cve Count
1
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a2bea10e617e2d8345887c3

Added to database: 06/12/2026, 11:14:24 UTC

Last enriched: 08/08/2026, 16:55:43 UTC

Last updated: 09/21/2026, 10:01:31 UTC

Views: 211

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses