CVE-2026-53434
published 2026-06-29CVE-2026-53434: Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat…
PriorityP260critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.37%
28.9th percentile
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.0 < 10.1.56 | 10.1.56 |
| apache | tomcat | >= 11.0.0 < 11.0.23 | 11.0.23 |
| apache | tomcat | >= 9.0.83 < 9.0.119 | 9.0.119 |
| apache_software_foundation | apache_tomcat | 10.1.0-M7 – 10.1.55 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.22 | — |
| apache_software_foundation | apache_tomcat | 9.0.83 – 9.0.118 | — |
| debian | tomcat10 | — | — |
| debian | tomcat11 | — | — |
| debian | tomcat9 | — | — |
| pki-deps_10.6 | pki-servlet-engine | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target Apache Tomcat deployments using the FFM-based connector (requires Java 22+ Foreign Function & Memory API) with CRL-based certificate revocation checking — the specific combination required for this vulnerability to be exploitable. ↗
- →Vulnerable Apache Tomcat version ranges: 11.0.0-M1 through 11.0.22, 10.1.0-M7 through 10.1.55, and 9.0.83 through 9.0.118. Detect unpatched instances by fingerprinting Tomcat version. ↗
- →The flaw may allow revoked certificates to be accepted as valid — monitor for TLS client authentication successes using certificates that should be revoked per CRL, especially on FFM-connector-enabled Tomcat instances. ↗
- ·Vulnerability ONLY affects Tomcat instances using the FFM-based connector (Foreign Function & Memory API, requires Java 22+) AND configured with CRL-based certificate revocation checking. Standard NIO/NIO2 connector deployments are NOT affected. ↗
- ·Red Hat Enterprise Linux packages across RHEL 6–10 and JBoss Web Server 5 have fixes deferred; only Red Hat Hardened Images (tomcat10, tomcat11) are listed as actively Affected with no deferred status — prioritize those environments. ↗
- ·The security bypass (accepting revoked certificates) only materialises when CRL data processing encounters an error that goes unhandled — misconfigured or malformed CRL files/endpoints could be a prerequisite or attack vector. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Tomcat up to 9.0.81/9.0.118/10.1.55/11.0.22 error condition (EUVD-2026-40228)
vuldb·2026-06-30
CVE-2026-53434 [CRITICAL] Apache Tomcat up to 9.0.81/9.0.118/10.1.55/11.0.22 error condition (EUVD-2026-40228)
A vulnerability categorized as critical has been discovered in Apache Tomcat up to 9.0.81/9.0.118/10.1.55/11.0.22. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to detection of error condition without action.
The identification of this vulnerability is CVE-2026-53434. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
ghsa_unreviewed·2026-06-29
CVE-2026-53434 [CRITICAL] CWE-390 Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
Red Hat
tomcat: Apache Tomcat: Error condition not handled when configuring CRLs
vendor_redhat·2026-06-29·CVSS 3.7
CVE-2026-53434 [LOW] CWE-390 tomcat: Apache Tomcat: Error condition not handled when configuring CRLs
tomcat: Apache Tomcat: Error condition not handled when configuring CRLs
A flaw was found in Apache Tomcat. When configuring Certificate Revocation Lists (CRLs) for a FFM (presumably a specific type of connector), the system fails to detect and act upon an error condition. This oversight could lead to unexpected behavior or a security bypass, as the intended security controls might not be properly enforced.
Statement: A flaw was found in Apache Tomcat. When using the FFM-based connector with CRL-based certificate revocation checking, an error in CRL data processing is not handled correctly, potentially allowing revoked certificates to be accepted. This only affects Tomcat 10.1.0-M7+ and 11.x using the FFM connector (Java 22+ Foreign Function & Memory API) with CRL configuration — an extr
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-53434 tomcat: Apache Tomcat: Error condition not handled when configuring CRLs [fedora-all]
bugzilla·2026-06-29
CVE-2026-53434 CVE-2026-53434 tomcat: Apache Tomcat: Error condition not handled when configuring CRLs [fedora-all]
CVE-2026-53434 tomcat: Apache Tomcat: Error condition not handled when configuring CRLs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
Bugzilla
CVE-2026-53434 tomcat: Apache Tomcat: Error condition not handled when configuring CRLs
bugzilla·2026-06-29
CVE-2026-53434 [LOW] CVE-2026-53434 tomcat: Apache Tomcat: Error condition not handled when configuring CRLs
CVE-2026-53434 tomcat: Apache Tomcat: Error condition not handled when configuring CRLs
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
2026-06-29
Published