cbcvebase.
CVE-2026-53434
published 2026-06-29

CVE-2026-53434: Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat…

PriorityP260critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.37%
28.9th percentile
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

Affected

11 ranges
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat>= 10.1.0 < 10.1.5610.1.56
apachetomcat>= 11.0.0 < 11.0.2311.0.23
apachetomcat>= 9.0.83 < 9.0.1199.0.119
apache_software_foundationapache_tomcat10.1.0-M7 – 10.1.55
apache_software_foundationapache_tomcat11.0.0-M1 – 11.0.22
apache_software_foundationapache_tomcat9.0.83 – 9.0.118
debiantomcat10
debiantomcat11
debiantomcat9
pki-deps_10.6pki-servlet-engine

Detection & IOCsextracted from sources · hover to see the quote

  • Target Apache Tomcat deployments using the FFM-based connector (requires Java 22+ Foreign Function & Memory API) with CRL-based certificate revocation checking — the specific combination required for this vulnerability to be exploitable.
  • Vulnerable Apache Tomcat version ranges: 11.0.0-M1 through 11.0.22, 10.1.0-M7 through 10.1.55, and 9.0.83 through 9.0.118. Detect unpatched instances by fingerprinting Tomcat version.
  • The flaw may allow revoked certificates to be accepted as valid — monitor for TLS client authentication successes using certificates that should be revoked per CRL, especially on FFM-connector-enabled Tomcat instances.
  • ·Vulnerability ONLY affects Tomcat instances using the FFM-based connector (Foreign Function & Memory API, requires Java 22+) AND configured with CRL-based certificate revocation checking. Standard NIO/NIO2 connector deployments are NOT affected.
  • ·Red Hat Enterprise Linux packages across RHEL 6–10 and JBoss Web Server 5 have fixes deferred; only Red Hat Hardened Images (tomcat10, tomcat11) are listed as actively Affected with no deferred status — prioritize those environments.
  • ·The security bypass (accepting revoked certificates) only materialises when CRL data processing encounters an error that goes unhandled — misconfigured or malformed CRL files/endpoints could be a prerequisite or attack vector.

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.