Skip to content

Improper Check for Certificate Revocation vulnerability in Apache Tomcat

Medium6.5CVE-2026-73581 · Published Sep 23, 2026 · updated Sep 30, 2026

Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0-M1 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.59, 9.0.122, which fixes the issue.

Affected versions

PackageAffectedFixed in
Apache Tomcat
Product
>= 11.0.0-M1, <= 11.0.25No fix yet
>= 10.1.0-M1, <= 10.1.59No fix yet
>= 9.0.0.M1, <= 9.0.121No fix yet
>= 8.5.0, <= 8.5.100No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Tomcat: authentication bypass
Critical9.8Sep 23
Apache Tomcat: race condition
High8.1Sep 23
Apache Sling XSS: cross-site scripting
Medium6.1Sep 23
Apache Sling XSS: cross-site scripting
Medium6.1Sep 23
Apache Sling XSS: cross-site scripting
Medium6.1Sep 23
Apache Sling XSS: cross-site scripting
Medium6.1Sep 23

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.