Executive brief
Apache Tomcat, a widely used web server and application container, contains a flaw in how it handles security certificate revocation lists (CRLs) when using specific modern connector configurations. If an error occurs while processing these lists, the system may fail to take appropriate action, potentially allowing revoked or invalid security certificates to be accepted. This could lead to unauthorized access or a breakdown in secure communications.
Technical details
Apache Tomcat is vulnerable to CWE-390 (Detection of Error Condition Without Action) within its Foreign Function Memory (FFM) based connector. When configuring Certificate Revocation Lists (CRLs), the application may detect an error condition but fail to execute the necessary security logic to handle it. This flaw could result in the failure to properly validate client certificates against revocation lists, potentially allowing revoked certificates to bypass security checks. The issue affects versions 11.0.0-M1 to 11.0.22, 10.1.0-M7 to 10.1.55, and 9.0.83 to 9.0.118. Users should upgrade to 11.0.23, 10.1.56, or 9.0.119 respectively.
Affected products
- Apache Tomcat 11.0.0-M1 through 11.0.22, 10.1.0-M7 through 10.1.55, 9.0.83 through 9.0.118
Timeline
- 2026-06-29: advisory
- 2026-06-29: disclosed