PT-2026-20317 · Apache+3 · Apache Tomcat Native+4

·

CVE-2026-24734

·

Published

2026-01-01

·

Updated

2026-08-19

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat Native versions 1.3.0 through 1.3.4 Apache Tomcat Native versions 2.0.0 through 2.0.11 Apache Tomcat versions 11.0.0-M1 through 11.0.17 Apache Tomcat versions 10.1.0-M7 through 10.1.51 Apache Tomcat versions 9.0.83 through 9.0.114 Apache Tomcat Native versions 1.1.23 through 1.1.34 Apache Tomcat Native versions 1.2.0 through 1.2.39
Description An improper input validation issue exists in Apache Tomcat Native and Apache Tomcat when using an OCSP responder. The software did not complete verification or freshness checks on the OCSP response, potentially allowing certificate revocation to be bypassed. The issue was reported on November 2, 2025, and made public on February 17, 2026.
Recommendations Apache Tomcat Native versions 1.3.5 or later should be used. Apache Tomcat Native versions 2.0.12 or later should be used. Apache Tomcat versions 11.0.18 or later should be used. Apache Tomcat versions 10.1.52 or later should be used. Apache Tomcat versions 9.0.115 or later should be used.

Exploit

Fix

DoS

Improper Certificate Validation

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:19054
ALSA-2026:26323
ALSA-2026:36790
BDU:2026-05104
BIT-TOMCAT-2026-24734
CVE-2026-24734
GHSA-MGP5-RV84-W37Q
MGASA-2026-0056
OESA-2026-1651
OPENSUSE-SU-2026:10305-1
OPENSUSE-SU-2026:10306-1
OPENSUSE-SU-2026:10307-1
OPENSUSE-SU-2026:20350-1
OPENSUSE-SU-2026:20414-1
OPENSUSE-SU-2026:20444-1
RHSA-2026:19054
RHSA-2026:26323
RHSA-2026:5611
RHSA-2026:6569
RHSA-2026:8334
SUSE-SU-2026:0877-1
SUSE-SU-2026:0890-1
SUSE-SU-2026:0932-1
SUSE-SU-2026:20926-1
SUSE-SU-2026:20982-1

Affected Products

Apache Tomcat
Apache Tomcat Native
Confluence
Red Os
Rocky Linux