CVE-2026-24734 is an improper input validation vulnerability in Apache Tomcat Native and Apache Tomcat, specifically affecting OCSP response verification. This flaw allows attackers to bypass certificate revocation checks due to incomplete verification or freshness checks. While no CVSS score is provided, its FAUCET Risk Score is 27/100, indicating a moderate risk. There is no evidence of active exploitation, nor are public exploit tools like Metasploit or ExploitDB modules available. However, the vulnerability has garnered some community discussion and media coverage, primarily concerning updates from openSUSE. Users are advised to upgrade to Apache Tomcat Native versions 1.3.5/2.0.12+ or Apache Tomcat versions 11.0.18+/10.1.52+/9.0.115+ to remediate the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0.83, < 9.0.115CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 10.1.1, < 10.1.52CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 11.0.1, < 11.0.18CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
10.1.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:* | ||
10.1.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:10.1.0:milestone10:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Tomcat has an Improper Input Validation vulnerability
Feb 17, 2026tomcat: Apache Tomcat: Certificate revocation bypass due to improper OCSP response validation
Feb 17, 2026[SECURITY] CVE-2026-24734 Apache Tomcat and Tomcat Native - OCSP revocation bypass
Feb 17, 2026