CVE-2026-34500: Apache Tomcat
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.
Affected products
- Apache Tomcat: from 9.0.92, before 9.0.117 (fixed in 9.0.117); from 10.1.22, before 10.1.54 (fixed in 10.1.54); from 11.0.1, before 11.0.21 (fixed in 11.0.21); version 11.0.0 only
Published 2026-04-09. Last modified 2026-06-17.