CVE-2026-86248: Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Apache Tomcat CVE-2026-86248 can soft-fail some OCSP checks during client-certificate authentication.
Apache disclosed CVE-2026-86248, a moderate Tomcat flaw in which the fix for CVE-2026-34500 was incomplete. With the foreign-function memory path, some OCSP checks can soft-fail even when soft-fail is disabled, so CLIENT_CERT authentication does not fail as expected. Affected ranges are Tomcat 11.0.0-M14 through 11.0.25, 10.1.22 through 10.1.59, and 9.0.92 through 9.0.121. The advisory does not report active exploitation.
- CVE-2026-86248 is an incomplete fix for CVE-2026-34500.
- OCSP checks can soft-fail with FFM even when soft-fail is disabled.
- CLIENT_CERT authentication may not fail in some expected scenarios.
- Apache rates the issue moderate; no exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-345006.5<1%CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcatpublished · apache tomcat
- CVE-2026-862489.8—Client-Certificate Authentication Bypass via OCSP Soft-Fail in Apache Tomcatpublished · Apache Tomcat
Posted by Mark Thomas on Sep 23 Severity: moderate Affected versions: - Apache Tomcat 11.0.0-M14 through 11.0.25 - Apache Tomcat 10.1.22 through 10.1.59 - Apache Tomcat 9.0.92 through 9.0.121 Description: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121. Users are...
This source does not provide full text. Read it at seclists.org.