CVE-2026-29145Improper Authentication in Software Foundation Apache Tomcat

Severity
9.1CRITICALNVD
EPSS
0.1%
top 69.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateApr 10

Description

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

CVEListV5apache_software_foundation/apache_tomcat11.0.0-M111.0.18+2

🔴Vulnerability Details

4
CVEList
Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled2026-04-09
GHSA
GHSA-95jq-rwvf-vjx4: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nativ2026-04-09
VulDB
Apache Tomcat up to 8.5.99/9.0.115/10.1.52/11.0.18 CLIENT_CERT Authentication improper authentication2026-04-09
GHSA
Apache Tomcat: CLIENT_CERT authentication does not fail as expected2026-04-09

📋Vendor Advisories

1
Red Hat
Apache Tomcat: Apache Tomcat: Authentication bypass due to CLIENT_CERT soft fail misconfiguration2026-04-09

💬Community

2
Bugzilla
CVE-2026-29145 tomcat: Apache Tomcat: Authentication bypass due to CLIENT_CERT soft fail misconfiguration [fedora-all]2026-04-10
Bugzilla
CVE-2026-29145 Apache Tomcat: Apache Tomcat: Authentication bypass due to CLIENT_CERT soft fail misconfiguration2026-04-09
CVE-2026-29145 — Improper Authentication | cvebase