CVE-2026-29145 Details
Description
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/04/09/23 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/yz5fxmhd2j43wgqykssdo7kltws57jfz | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | >= 9.0.83, < 9.0.116 >= 10.1.1, < 10.1.53 >= 11.0.0, < 11.0.20 10.1.0 - 10.1.0 milestone10 10.1.0 milestone11 10.1.0 milestone12 10.1.0 milestone13 10.1.0 milestone14 10.1.0 milestone15 10.1.0 milestone16 10.1.0 milestone17 10.1.0 milestone18 10.1.0 milestone19 10.1.0 milestone20 10.1.0 milestone7 10.1.0 milestone8 10.1.0 milestone9 |
CPE
Remediation
| |
| apache tomcat native | >= 1.1.23, < 1.3.7 >= 2.0.0, < 2.0.14 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 10, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | CVE Modified | CVE |
| Apr 9, 2026 | New CVE Received | [email protected] |