Improper Certificate Validation in Apache Tomcat - CVE-2026-53434
Published: June 30, 2026
Apache Tomcat
Detailed vulnerability description
The vulnerability allows a remote attacker to authenticate with an invalid certificate.
The vulnerability exists due to improper certificate revocation validation in the FFM Connector when handling connections with invalid CRL configuration. A remote attacker can present an invalid certificate to authenticate with an invalid certificate.
Only configurations using the FFM Connector with invalid CRLs are affected.
How to mitigate CVE-2026-53434
Sources
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.56
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.23
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.119
- https://github.com/apache/tomcat/commit/feec60d6099727db6f911534f6a0f6926ebab070