MEDIUM6.5
GHSA-24j9-x2wg-9qv6
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
Quick fix
GHSA-24j9-x2wg-9qv6 — org.apache.tomcat:tomcat-coyote-ffm: upgrade to the fixed version with the command below.
# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat-coyote-ffmDetails
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.tomcat:tomcat-coyote-ffm
Introduced in:
9.0.92Fixed in: 9.0.117Fix
# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat-coyote-ffmMaven/org.apache.tomcat:tomcat-coyote-ffm
Introduced in:
10.1.22Fixed in: 10.1.54Fix
# pom.xml: bump <version>10.1.54</version> for org.apache.tomcat:tomcat-coyote-ffmMaven/org.apache.tomcat:tomcat-coyote-ffm
Introduced in:
11.0.0-M14Fixed in: 11.0.21Fix
# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat:tomcat-coyote-ffmReferences
- https://nvd.nist.gov/vuln/detail/CVE-2026-34500[ADVISORY]
- https://github.com/apache/tomcat/commit/29b56a56ce9e7d044b6162a99af0f38529b3a208[WEB]
- https://github.com/apache/tomcat/commit/c13e60e732ea6d07087293a41ad1866c20848271[WEB]
- https://github.com/apache/tomcat/commit/ff589ab26e8250a2ca4286d986305318c033ff9f[WEB]
- https://github.com/apache/tomcat[PACKAGE]
- https://lists.apache.org/thread/7rcl4zdxryc8hy3htyfyxkbqpxjtfdl2[WEB]
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.54[WEB]
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.21[WEB]
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.117[WEB]
- http://www.openwall.com/lists/oss-security/2026/04/09/29[WEB]