GHSA-95jq-rwvf-vjx4

Suggest an improvement
Source
https://github.com/advisories/GHSA-95jq-rwvf-vjx4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-95jq-rwvf-vjx4
Aliases
Downstream
CGA (40)
Published
2026-04-09T21:31:29Z
Modified
2026-09-10T03:51:01Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
Details

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13.

Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.

Database specific
{
    "cwe_ids":  [
        "CWE-287"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-10T22:07:25Z",
    "nvd_published_at":  "2026-04-09T20:16:24Z",
    "severity":  "CRITICAL"
}
References

Affected packages

Maven
org.apache.tomcat:tomcat-coyote-ffm

Package

Name
org.apache.tomcat:tomcat-coyote-ffm
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat-coyote-ffm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.0.83
Fixed
9.0.116

Affected versions

9.*
9.0.93
9.0.94
9.0.95
9.0.96
9.0.97
9.0.98
9.0.99
9.0.100
9.0.102
9.0.104
9.0.105
9.0.106
9.0.107
9.0.108
9.0.109
9.0.110
9.0.111
9.0.112
9.0.113
9.0.115

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json"
org.apache.tomcat:tomcat-coyote-ffm

Package

Name
org.apache.tomcat:tomcat-coyote-ffm
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat-coyote-ffm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
10.1.0-M7
Fixed
10.1.53

Affected versions

10.*
10.1.26
10.1.28
10.1.29
10.1.30
10.1.31
10.1.33
10.1.34
10.1.35
10.1.36
10.1.39
10.1.40
10.1.41
10.1.42
10.1.43
10.1.44
10.1.45
10.1.46
10.1.47
10.1.48
10.1.49
10.1.50
10.1.52

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json"
org.apache.tomcat:tomcat-coyote-ffm

Package

Name
org.apache.tomcat:tomcat-coyote-ffm
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat-coyote-ffm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
11.0.0-M1
Fixed
11.0.20

Affected versions

11.*
11.0.0-M22
11.0.0-M24
11.0.0-M25
11.0.0-M26
11.0.0
11.0.1
11.0.2
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
11.0.9
11.0.10
11.0.11
11.0.12
11.0.13
11.0.14
11.0.15
11.0.18

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json"
org.apache.tomcat:tomcat

Package

Name
org.apache.tomcat:tomcat
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.0.83
Fixed
9.0.116

Affected versions

9.*
9.0.83
9.0.84
9.0.85
9.0.86
9.0.87
9.0.88
9.0.89
9.0.90
9.0.91
9.0.93
9.0.94
9.0.95
9.0.96
9.0.97
9.0.98
9.0.99
9.0.100
9.0.102
9.0.104
9.0.105
9.0.106
9.0.107
9.0.108
9.0.109
9.0.110
9.0.111
9.0.112
9.0.113
9.0.115

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json"
org.apache.tomcat:tomcat

Package

Name
org.apache.tomcat:tomcat
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat

Affected ranges

Type
ECOSYSTEM
Events
Introduced
10.1.0-M7
Fixed
10.1.53

Affected versions

10.*
10.1.0-M7
10.1.0-M8
10.1.0-M10
10.1.0-M11
10.1.0-M12
10.1.0-M14
10.1.0-M15
10.1.0-M16
10.1.0-M17
10.1.0
10.1.1
10.1.2
10.1.4
10.1.5
10.1.6
10.1.7
10.1.8
10.1.9
10.1.10
10.1.11
10.1.12
10.1.13
10.1.14
10.1.15
10.1.16
10.1.17
10.1.18
10.1.19
10.1.20
10.1.23
10.1.24
10.1.25
10.1.26
10.1.28
10.1.29
10.1.30
10.1.31
10.1.33
10.1.34
10.1.35
10.1.36
10.1.39
10.1.40
10.1.41
10.1.42
10.1.43
10.1.44
10.1.45
10.1.46
10.1.47
10.1.48
10.1.49
10.1.50
10.1.52

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json"
org.apache.tomcat:tomcat

Package

Name
org.apache.tomcat:tomcat
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat

Affected ranges

Type
ECOSYSTEM
Events
Introduced
11.0.0-M1
Fixed
11.0.20

Affected versions

11.*
11.0.0-M1
11.0.0-M3
11.0.0-M4
11.0.0-M5
11.0.0-M6
11.0.0-M7
11.0.0-M9
11.0.0-M10
11.0.0-M11
11.0.0-M12
11.0.0-M13
11.0.0-M14
11.0.0-M15
11.0.0-M16
11.0.0-M17
11.0.0-M18
11.0.0-M19
11.0.0-M20
11.0.0-M21
11.0.0-M22
11.0.0-M24
11.0.0-M25
11.0.0-M26
11.0.0
11.0.1
11.0.2
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
11.0.9
11.0.10
11.0.11
11.0.12
11.0.13
11.0.14
11.0.15
11.0.18

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-95jq-rwvf-vjx4/GHSA-95jq-rwvf-vjx4.json"