Junglewise Threat Intelligence

CVE-2026-53434: Apache Tomcat improper error handling in FFM connector CRL configuration

CVE-2026-53434 · Severity: info · Published 2026-06-29

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat, a widely used web server and application container, contains a flaw in how it handles security certificate revocation lists (CRLs) when using specific modern connector configurations. If an error occurs while processing these lists, the system may fail to take appropriate action, potentially allowing revoked or invalid security certificates to be accepted. This could lead to unauthorized access or a breakdown in secure communications.

Technical details

Apache Tomcat is vulnerable to CWE-390 (Detection of Error Condition Without Action) within its Foreign Function Memory (FFM) based connector. When configuring Certificate Revocation Lists (CRLs), the application may detect an error condition but fail to execute the necessary security logic to handle it. This flaw could result in the failure to properly validate client certificates against revocation lists, potentially allowing revoked certificates to bypass security checks. The issue affects versions 11.0.0-M1 to 11.0.22, 10.1.0-M7 to 10.1.55, and 9.0.83 to 9.0.118. Users should upgrade to 11.0.23, 10.1.56, or 9.0.119 respectively.

Affected products

  • Apache Tomcat 11.0.0-M1 through 11.0.22, 10.1.0-M7 through 10.1.55, 9.0.83 through 9.0.118

Timeline

  • 2026-06-29: advisory
  • 2026-06-29: disclosed

References

Related threats