{"schema_version":"1.7.5","id":"GHSA-24j9-x2wg-9qv6","published":"2026-04-09T21:31:30Z","modified":"2026-05-20T02:30:10.811261922Z","aliases":["BIT-tomcat-2026-34500","CVE-2026-34500"],"related":["CGA-5gch-j3p7-3556"],"summary":"Apache Tomcat: CLIENT_CERT authentication does not fail as expected","details":"CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.\n\nUsers are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.","affected":[{"package":{"name":"org.apache.tomcat:tomcat-coyote-ffm","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-coyote-ffm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.92"},{"fixed":"9.0.117"}]}],"versions":["9.0.100","9.0.102","9.0.104","9.0.105","9.0.106","9.0.107","9.0.108","9.0.109","9.0.110","9.0.111","9.0.112","9.0.113","9.0.115","9.0.116","9.0.93","9.0.94","9.0.95","9.0.96","9.0.97","9.0.98","9.0.99"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-24j9-x2wg-9qv6/GHSA-24j9-x2wg-9qv6.json"}},{"package":{"name":"org.apache.tomcat:tomcat-coyote-ffm","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-coyote-ffm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.22"},{"fixed":"10.1.54"}]}],"versions":["10.1.26","10.1.28","10.1.29","10.1.30","10.1.31","10.1.33","10.1.34","10.1.35","10.1.36","10.1.39","10.1.40","10.1.41","10.1.42","10.1.43","10.1.44","10.1.45","10.1.46","10.1.47","10.1.48","10.1.49","10.1.50","10.1.52","10.1.53"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-24j9-x2wg-9qv6/GHSA-24j9-x2wg-9qv6.json"}},{"package":{"name":"org.apache.tomcat:tomcat-coyote-ffm","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-coyote-ffm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0-M14"},{"fixed":"11.0.21"}]}],"versions":["11.0.0","11.0.0-M22","11.0.0-M24","11.0.0-M25","11.0.0-M26","11.0.1","11.0.10","11.0.11","11.0.12","11.0.13","11.0.14","11.0.15","11.0.18","11.0.2","11.0.20","11.0.3","11.0.4","11.0.5","11.0.6","11.0.7","11.0.8","11.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-24j9-x2wg-9qv6/GHSA-24j9-x2wg-9qv6.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34500"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/29b56a56ce9e7d044b6162a99af0f38529b3a208"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/c13e60e732ea6d07087293a41ad1866c20848271"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/ff589ab26e8250a2ca4286d986305318c033ff9f"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"https://lists.apache.org/thread/7rcl4zdxryc8hy3htyfyxkbqpxjtfdl2"},{"type":"WEB","url":"https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.54"},{"type":"WEB","url":"https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.21"},{"type":"WEB","url":"https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.117"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/09/29"}],"database_specific":{"cwe_ids":["CWE-287"],"github_reviewed":true,"github_reviewed_at":"2026-04-10T21:38:56Z","nvd_published_at":"2026-04-09T20:16:25Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}