Skip to main content

Vendor/product archive

apache / tomcat_native CVEs

Beta · best-effort

5 CVEs tagged to apache / tomcat_native1 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-29145

Published Apr 9, 2026

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24734

Published Feb 17, 2026

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did…

CVSS 7.5 · High
evidence mentions
11
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2018-8020

Published Jul 31, 2018

Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate st…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8019

Published Jul 31, 2018

When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15698

Published Jan 31, 2018

When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 b…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1