PT-2026-97281 · Openssl+1 · Openssl+1

·

CVE-2026-73581

·

Published

2026-09-15

·

Updated

2026-10-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.25 Apache Tomcat versions 10.1.0-M1 through 10.1.58 Apache Tomcat versions 9.0.0-M1 through 9.0.121 Apache Tomcat versions 8.5.0 through 8.5.100
Description An improper check for certificate revocation exists where both OpenSSL and OpenSSL-FFM TLS implementations ignore Certificate Revocation Lists (CRLs)—lists of digital certificates that have been revoked by the issuing certificate authority before their scheduled expiration date—when a certificate uses a keystore.
Recommendations Upgrade to version 11.0.26 Upgrade to version 10.1.59 Upgrade to version 9.0.122

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TOMCAT-2026-73581
CVE-2026-73581
OPENSUSE-SU-2026:11906-1
OPENSUSE-SU-2026:11907-1
OPENSUSE-SU-2026:11908-1
OPENSUSE-SU-2026:21984-1

Affected Products

Apache Tomcat
Openssl