CVE-2026-53434
Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
Description
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
In plain language
AI Worth attentionIf you run Apache Tomcat using an FFM-based connector with CRL (certificate revocation) settings, Tomcat may accept an invalid CRL without failing—so you could end up with weaker certificate checking than you intended; small businesses should act by upgrading to the fixed Tomcat versions.
In Apache Tomcat, an invalid CRL configured for an FFM-based connector can fail to trigger the expected error handling, so security checks may be bypassed due to “detection of error condition without action” (CWE-390); this can allow unauthorized access or trust violations without any authentication or user interaction.
What to do now
- Check whether your Apache Tomcat (9.0, 10.1, or 11.0) is within the affected version ranges (9.0.83–9.0.118, 10.1.0-M7–10.1.55, 11.0.0-M1–11.0.22).
- Verify whether you use a CRL configuration with an FFM-based connector in Tomcat (this issue only applies when CRL is used with that connector type).
- If you are affected, upgrade Apache Tomcat to 9.0.119 (or 10.1.56+ / 11.0.23+ if you’re on those branches) to ensure invalid CRLs correctly trigger failure.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-53434 and every CVE in our database. Create a free account — no credit card required.
Create Free Account