{"schema_version":"1.7.5","id":"GHSA-95jq-rwvf-vjx4","published":"2026-04-09T21:31:29Z","modified":"2026-05-20T22:15:12.386663348Z","aliases":["BIT-tomcat-2026-29145","CVE-2026-29145"],"related":["CGA-w4c6-8mq2-4848"],"summary":"Apache Tomcat: CLIENT_CERT authentication does not fail as expected","details":"CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13.\n\nUsers are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.","affected":[{"package":{"name":"org.apache.tomcat:tomcat-coyote-ffm","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-coyote-ffm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.83"},{"fixed":"9.0.116"}]}],"versions":["9.0.100","9.0.102","9.0.104","9.0.105","9.0.106","9.0.107","9.0.108","9.0.109","9.0.110","9.0.111","9.0.112","9.0.113","9.0.115","9.0.93","9.0.94","9.0.95","9.0.96","9.0.97","9.0.98","9.0.99"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json"}},{"package":{"name":"org.apache.tomcat:tomcat-coyote-ffm","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-coyote-ffm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.0-M7"},{"fixed":"10.1.53"}]}],"versions":["10.1.26","10.1.28","10.1.29","10.1.30","10.1.31","10.1.33","10.1.34","10.1.35","10.1.36","10.1.39","10.1.40","10.1.41","10.1.42","10.1.43","10.1.44","10.1.45","10.1.46","10.1.47","10.1.48","10.1.49","10.1.50","10.1.52"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json"}},{"package":{"name":"org.apache.tomcat:tomcat-coyote-ffm","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-coyote-ffm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0-M1"},{"fixed":"11.0.20"}]}],"versions":["11.0.0","11.0.0-M22","11.0.0-M24","11.0.0-M25","11.0.0-M26","11.0.1","11.0.10","11.0.11","11.0.12","11.0.13","11.0.14","11.0.15","11.0.18","11.0.2","11.0.3","11.0.4","11.0.5","11.0.6","11.0.7","11.0.8","11.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.83"},{"fixed":"9.0.116"}]}],"versions":["9.0.100","9.0.102","9.0.104","9.0.105","9.0.106","9.0.107","9.0.108","9.0.109","9.0.110","9.0.111","9.0.112","9.0.113","9.0.115","9.0.83","9.0.84","9.0.85","9.0.86","9.0.87","9.0.88","9.0.89","9.0.90","9.0.91","9.0.93","9.0.94","9.0.95","9.0.96","9.0.97","9.0.98","9.0.99"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.0-M7"},{"fixed":"10.1.53"}]}],"versions":["10.1.0","10.1.0-M10","10.1.0-M11","10.1.0-M12","10.1.0-M14","10.1.0-M15","10.1.0-M16","10.1.0-M17","10.1.0-M7","10.1.0-M8","10.1.1","10.1.10","10.1.11","10.1.12","10.1.13","10.1.14","10.1.15","10.1.16","10.1.17","10.1.18","10.1.19","10.1.2","10.1.20","10.1.23","10.1.24","10.1.25","10.1.26","10.1.28","10.1.29","10.1.30","10.1.31","10.1.33","10.1.34","10.1.35","10.1.36","10.1.39","10.1.4","10.1.40","10.1.41","10.1.42","10.1.43","10.1.44","10.1.45","10.1.46","10.1.47","10.1.48","10.1.49","10.1.5","10.1.50","10.1.52","10.1.6","10.1.7","10.1.8","10.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0-M1"},{"fixed":"11.0.20"}]}],"versions":["11.0.0","11.0.0-M1","11.0.0-M10","11.0.0-M11","11.0.0-M12","11.0.0-M13","11.0.0-M14","11.0.0-M15","11.0.0-M16","11.0.0-M17","11.0.0-M18","11.0.0-M19","11.0.0-M20","11.0.0-M21","11.0.0-M22","11.0.0-M24","11.0.0-M25","11.0.0-M26","11.0.0-M3","11.0.0-M4","11.0.0-M5","11.0.0-M6","11.0.0-M7","11.0.0-M9","11.0.1","11.0.10","11.0.11","11.0.12","11.0.13","11.0.14","11.0.15","11.0.18","11.0.2","11.0.3","11.0.4","11.0.5","11.0.6","11.0.7","11.0.8","11.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29145"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/721591f7bff424c693f26adc18ae9b9abac3655b"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/d1406df5ae0326f39f54c3f64ac30d8fca55cd5b"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/fe26667cd2385045ac73f4dea086cc9971209b90"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"https://lists.apache.org/thread/yz5fxmhd2j43wgqykssdo7kltws57jfz"},{"type":"WEB","url":"https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.53"},{"type":"WEB","url":"https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20"},{"type":"WEB","url":"https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.116"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/09/23"}],"database_specific":{"cwe_ids":["CWE-287"],"github_reviewed":true,"github_reviewed_at":"2026-04-10T22:07:25Z","nvd_published_at":"2026-04-09T20:16:24Z","severity":"CRITICAL"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}