Improper Certificate Validation in Apache Tomcat - CVE-2026-73581
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass certificate revocation checks.
The vulnerability exists due to improper certificate validation in the OpenSSL and OpenSSL-FFM TLS implementations when validating a certificate that uses a keystore. A remote attacker can present a certificate subject to certificate revocation checks to bypass certificate revocation checks.
The issue affects both the OpenSSL and OpenSSL-FFM TLS implementations when the certificate uses a keystore.