blob: 5a3cb685a3a70421716186f496a3d5c8aabeb3b4 [file]
<!DOCTYPE html SYSTEM "about:legacy-compat">
<html lang="en"><head><META http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat APR/native Connector vulnerabilities</title><meta name="author" content="Apache Tomcat Project"><script src="https://www.apachecon.com/event-images/snippet.js"></script></head><body><div id="wrapper"><header id="header"><div class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div class="hamburger"></div></div><a href="http://tomcat.apache.org/"><img class="tomcat-logo pull-left noPrint" alt="Tomcat Home" src="res/images/tomcat.png"></a><h1 class="pull-left">Apache Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a href="https://www.apache.org/foundation/contributing.html" target="_blank" class="pull-left"><img src="https://www.apache.org/images/SupportApache-small.png" class="support-asf" alt="Support Apache"></a><a href="http://www.apache.org/" target="_blank" class="pull-left"><img src="res/images/asf_logo_wide.svg" class="asf-logo" alt="The Apache Software Foundation"></a></div></div></header><main id="middle"><div><div id="mainLeft"><div id="nav-wrapper"><form action="https://www.google.com/search" method="get"><div class="searchbox"><input value="tomcat.apache.org" name="sitesearch" type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" required="required" name="q" id="query" type="search"><button>GO</button></div></form><div class="asfevents"><a class="acevent" data-format="square" data-width="150"></a></div><nav><div><h2>Apache Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a href="./whichversion.html">Which version?</a></li><li><a href="https://tomcat.apache.org/download-11.cgi">Tomcat 11</a></li><li><a href="https://tomcat.apache.org/download-10.cgi">Tomcat 10</a></li><li><a href="https://tomcat.apache.org/download-90.cgi">Tomcat 9</a></li><li><a href="https://tomcat.apache.org/download-migration.cgi">Tomcat Migration Tool for Jakarta EE</a></li><li><a href="https://tomcat.apache.org/download-connectors.cgi">Tomcat Connectors</a></li><li><a href="https://tomcat.apache.org/download-native.cgi">Tomcat Native</a></li><li><a href="https://tomcat.apache.org/download-taglibs.cgi">Taglibs</a></li><li><a href="https://archive.apache.org/dist/tomcat/">Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a href="./tomcat-11.0-doc/index.html">Tomcat 11.0</a></li><li><a href="./tomcat-10.1-doc/index.html">Tomcat 10.1</a></li><li><a href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a href="./upgrading.html">Upgrading</a></li><li><a href="./connectors-doc/index.html">Tomcat Connectors</a></li><li><a href="./native-doc/index.html">Tomcat Native 2</a></li><li><a href="./native-1.3-doc/index.html">Tomcat Native 1.3</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT">Wiki</a></li><li><a href="./migration.html">Migration Guide</a></li><li><a href="./presentations.html">Presentations</a></li><li><a href="https://cwiki.apache.org/confluence/x/Bi8lBg">Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a href="./security.html">Security Reports</a></li><li><a href="./findhelp.html">Find help</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ">FAQ</a></li><li><a href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug Database</a></li></ul></div><div><h2>Get Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a href="./source.html">Source code</a></li><li><a href="./ci.html">Buildbot</a></li><li><a href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a href="https://www.youtube.com/c/ApacheTomcatOfficial">YouTube</a></li></ul></div><div><h2>Misc</h2><ul><li><a href="./whoweare.html">Who We Are</a></li><li><a href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat">Swag</a></li><li><a href="./heritage.html">Heritage</a></li><li><a href="http://www.apache.org">Apache Home</a></li><li><a href="./resources.html">Resources</a></li><li><a href="./contact.html">Contact</a></li><li><a href="./legal.html">Legal</a></li><li><a href="https://privacy.apache.org/policies/privacy-policy-public.html">Privacy</a></li><li><a href="https://www.apache.org/foundation/contributing.html">Support Apache</a></li><li><a href="https://www.apache.org/foundation/sponsorship.html">Sponsorship</a></li><li><a href="http://www.apache.org/foundation/thanks.html">Thanks</a></li><li><a href="http://www.apache.org/licenses/">License</a></li></ul></div></nav></div></div><div id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 id="Table_of_Contents">Table of Contents</h3><div class="text">
<ul><li><a href="#Apache_Tomcat_APR/native_Connector_vulnerabilities">Apache Tomcat APR/native Connector vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_Native_Connector_2.0.14_/_1.3.7">Fixed in Apache Tomcat Native Connector 2.0.14 / 1.3.7</a></li><li><a href="#Fixed_in_Apache_Tomcat_Native_Connector_2.0.12_/_1.3.5">Fixed in Apache Tomcat Native Connector 2.0.12 / 1.3.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_Native_Connector_1.2.17">Fixed in Apache Tomcat Native Connector 1.2.17</a></li><li><a href="#Fixed_in_Apache_Tomcat_Native_Connector_1.2.16">Fixed in Apache Tomcat Native Connector 1.2.16</a></li><li><a href="#Not_a_vulnerability_in_the_Apache_Tomcat_APR/native_Connector">Not a vulnerability in the Apache Tomcat APR/native Connector</a></li></ul>
</div><h3 id="Apache_Tomcat_APR/native_Connector_vulnerabilities">Apache Tomcat APR/native Connector vulnerabilities</h3><div class="text">
<p>This page lists all security vulnerabilities fixed in released versions
of Apache Tomcat APR/native Connector. Each vulnerability is given a
<a href="security-impact.html">security impact rating</a> by the Apache
Tomcat<sup>&reg;</sup> security team &mdash; please note that this rating may vary from
platform to platform. We also list the versions of Apache Tomcat APR/native
Connectors the flaw is known to affect, and where a flaw has not been
verified list the version with a question mark.</p>
<p><strong>Note:</strong> Vulnerabilities that are not Tomcat vulnerabilities
but have either been incorrectly reported against Tomcat or where Tomcat
provides a workaround are listed at the end of this page.</p>
<p>This page has been created from a review of the Apache Tomcat archives
and the CVE list. Please send comments or corrections for these
vulnerabilities to the <a href="security.html">Tomcat
Security Team</a>.</p>
</div><h3 id="Fixed_in_Apache_Tomcat_Native_Connector_2.0.14_/_1.3.7">Fixed in Apache Tomcat Native Connector 2.0.14 / 1.3.7</h3><div class="text">
<p><strong>Moderate: OCSP checks sometimes soft-fail even when soft-fail is
disabled</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29145" rel="nofollow">CVE-2026-29145</a></p>
<p>CLIENT_CERT authentication did not fail OCSP checks as expected for some
scenarios when soft fail was disabled.</p>
<p>This was fixed with commit
<a href="https://github.com/apache/tomcat-native/commit/bcea0ac214cae14fd1c2517d759a72465cfc62d3">bcea0ac2</a>
()2.0.x) and
<a href="https://github.com/apache/tomcat-native/commit/204f7f8a09adffce7ad02998dbc902f2b8c87253">204f7f8a</a>
(1.3.x).</p>
<p>This issue was reported to the Tomcat security team on 26 February 2026.
The issue was made public on 9 April 2026.</p>
<p>Affects: 1.3.0 to 1.3.6 and 2.0.0 to 2.0.13</p>
</div><h3 id="Fixed_in_Apache_Tomcat_Native_Connector_2.0.12_/_1.3.5">Fixed in Apache Tomcat Native Connector 2.0.12 / 1.3.5</h3><div class="text">
<p><strong>Moderate: Incomplete OCSP verification checks</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24734" rel="nofollow">CVE-2026-24734</a></p>
<p>When using an OCSP responder, Tomcat Native did complete verification or
freshness checks on the OCSP response which could allow certificate
revocation to be bypassed.</p>
<p>This issue was reported to the Tomcat security team on 2 November 2025.
The issue was made public on 17 February 2026.</p>
<p>Affects: 1.3.0 to 1.3.4 and 2.0.0 to 2.0.11</p>
</div><h3 id="Fixed_in_Apache_Tomcat_Native_Connector_1.2.17">Fixed in Apache Tomcat Native Connector 1.2.17</h3><div class="text">
<p><strong>Moderate: Mishandled OCSP invalid response</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8019" rel="nofollow">CVE-2018-8019</a></p>
<p>When using an OCSP responder Tomcat Native did not correctly handle
invalid responses. This allowed for revoked client certificates to
be incorrectly identified. It was therefore possible for users to
authenticate with revoked certificates when using mutual TLS.</p>
<p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&amp;rev=1832832">1832832</a>.</p>
<p>Affects: 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34</p>
<p><strong>Important: Mishandled OCSP responses can allow clients to
authenticate with revoked certificates</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8020" rel="nofollow">CVE-2018-8020</a></p>
<p>Apache Tomcat Native has a flaw that does not properly check OCSP
pre-produced responses, which are lists (multiple entries) of
certificate statuses. Subsequently, revoked client certificates may not be
properly identified, allowing for users to authenticate with revoked
certicates to connections that require mutual TLS.</p>
<p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&amp;rev=1832863">1832863</a>.</p>
<p>Affects: 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34</p>
</div><h3 id="Fixed_in_Apache_Tomcat_Native_Connector_1.2.16">Fixed in Apache Tomcat Native Connector 1.2.16</h3><div class="text">
<p><i>Note: The issue below was fixed in Apache Tomcat Native Connector
1.2.15 but the release vote for the 1.2.15 release candidate did not
pass. Therefore, although users must download 1.2.16 to obtain a version
that includes the fix for this issue, version 1.2.15 is not included in
the list of affected versions.</i></p>
<p><strong>Moderate: OCSP check omitted</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15698" rel="nofollow">CVE-2017-15698</a></p>
<p>When parsing the AIA-Extension field of a client certificate, the Apache
Tomcat Native Connector did not correctly handle fields longer than 127
bytes. The result of the parsing error was to skip the OCSP check. It was
therefore possible for client certificates that should have been rejected
(if the OCSP check had been made) to be accepted. Users not using OCSP
checks are not affected by this vulnerability.
</p>
<p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&amp;rev=1815200">1815200</a> and
<a href="https://svn.apache.org/viewvc?view=rev&amp;rev=1815218">1815218</a>.</p>
<p>This issue was reported to the Apache Tomcat Security Team by Jonas
Klempel on 6 November 2017 and made public on 31 January 2018.</p>
<p>Affects: 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34</p>
</div><h3 id="Not_a_vulnerability_in_the_Apache_Tomcat_APR/native_Connector">Not a vulnerability in the Apache Tomcat APR/native Connector</h3><div class="text">
<p><strong>TLS SSL Man In The Middle</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555" rel="nofollow">CVE-2009-3555</a></p>
<p>A vulnerability exists in the TLS protocol that allows an attacker to
inject arbitrary requests into an TLS stream during renegotiation.</p>
<p>The TLS implementation used by Tomcat varies with connector. The
APR/native connector uses OpenSSL.</p>
<p>The APR/native connector is vulnerable if the OpenSSL version used is
vulnerable. Note: Building with OpenSSL 0.9.8l will disable all
renegotiation and protect against this vulnerability.</p>
<p>From 1.1.18 onwards, client initiated renegotiations are rejected to
provide partial protection against this vulnerability with any OpenSSL
version.</p>
<p>Users should be aware that the impact of disabling renegotiation will
vary with both application and client. In some circumstances disabling
renegotiation may result in some clients being unable to access the
application.</p>
<p><strong>Important: Remote Memory Read</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160" rel="nofollow">CVE-2014-0160</a> (a.k.a. "Heartbleed")</p>
<p>A bug in certain versions of <a href="www.openssl.org">OpenSSL</a>
can allow an unauthenticated remote user to read certain contents of
the server's memory. Binary versions of tcnative 1.1.24 - 1.1.29
include this vulnerable version of OpenSSL. tcnative 1.1.30 and later
ship with patched versions of OpenSSL.</p>
<p>This issue was first announced on 7 April 2014.</p>
<p>Affects: OpenSSL 1.0.1-1.0.1f, tcnative 1.1.24-1.1.29</p>
</div></div></div></div></main><footer id="footer">
Copyright &copy; 1999-2026, The Apache Software Foundation
<br>
Apache Tomcat, Tomcat, Apache, the Apache Tomcat logo and the Apache logo
are either registered trademarks or trademarks of the Apache Software
Foundation.
</footer></div><script src="res/js/tomcat.js"></script></body></html>