CVE Tools

CVE-2026-53434

Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector

Published: Jun 29, 2026Updated: Jul 2, 2026 Sources: CVE List NVDCWE-390

Description

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

In plain language

AI Worth attention

If you run Apache Tomcat using an FFM-based connector with CRL (certificate revocation) settings, Tomcat may accept an invalid CRL without failing—so you could end up with weaker certificate checking than you intended; small businesses should act by upgrading to the fixed Tomcat versions.

Executive summary

In Apache Tomcat, an invalid CRL configured for an FFM-based connector can fail to trigger the expected error handling, so security checks may be bypassed due to “detection of error condition without action” (CWE-390); this can allow unauthorized access or trust violations without any authentication or user interaction.

If affected, business impact
Unauthorized access via weak trustCertificate trust checking bypassSecurity policy misconfiguration acceptancePotential data exposure

What to do now

  1. Check whether your Apache Tomcat (9.0, 10.1, or 11.0) is within the affected version ranges (9.0.83–9.0.118, 10.1.0-M7–10.1.55, 11.0.0-M1–11.0.22).
  2. Verify whether you use a CRL configuration with an FFM-based connector in Tomcat (this issue only applies when CRL is used with that connector type).
  3. If you are affected, upgrade Apache Tomcat to 9.0.119 (or 10.1.56+ / 11.0.23+ if you’re on those branches) to ensure invalid CRLs correctly trigger failure.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:NAvailability
None

Weaknesses

Affected Products

apache
oss-project·USaka apache httpd, apache http server

Exploitability

Official Patch Available

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-53434 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows