Vulnerability Details CVE-2026-29145
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13.
Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.4%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2026-29145
-
cpe:2.3:a:apache:tomcat:10.1.0
-
cpe:2.3:a:apache:tomcat:10.1.1
-
cpe:2.3:a:apache:tomcat:10.1.10
-
cpe:2.3:a:apache:tomcat:10.1.11
-
cpe:2.3:a:apache:tomcat:10.1.12
-
cpe:2.3:a:apache:tomcat:10.1.13
-
cpe:2.3:a:apache:tomcat:10.1.14
-
cpe:2.3:a:apache:tomcat:10.1.15
-
cpe:2.3:a:apache:tomcat:10.1.16
-
cpe:2.3:a:apache:tomcat:10.1.17
-
cpe:2.3:a:apache:tomcat:10.1.18
-
cpe:2.3:a:apache:tomcat:10.1.19
-
cpe:2.3:a:apache:tomcat:10.1.2
-
cpe:2.3:a:apache:tomcat:10.1.20
-
cpe:2.3:a:apache:tomcat:10.1.22
-
cpe:2.3:a:apache:tomcat:10.1.23
-
cpe:2.3:a:apache:tomcat:10.1.24
-
cpe:2.3:a:apache:tomcat:10.1.25
-
cpe:2.3:a:apache:tomcat:10.1.26
-
cpe:2.3:a:apache:tomcat:10.1.27
-
cpe:2.3:a:apache:tomcat:10.1.28
-
cpe:2.3:a:apache:tomcat:10.1.29
-
cpe:2.3:a:apache:tomcat:10.1.30
-
cpe:2.3:a:apache:tomcat:10.1.31
-
cpe:2.3:a:apache:tomcat:10.1.32
-
cpe:2.3:a:apache:tomcat:10.1.33
-
cpe:2.3:a:apache:tomcat:10.1.34
-
cpe:2.3:a:apache:tomcat:10.1.35
-
cpe:2.3:a:apache:tomcat:10.1.36
-
cpe:2.3:a:apache:tomcat:10.1.37
-
cpe:2.3:a:apache:tomcat:10.1.38
-
cpe:2.3:a:apache:tomcat:10.1.39
-
cpe:2.3:a:apache:tomcat:10.1.40
-
cpe:2.3:a:apache:tomcat:10.1.41
-
cpe:2.3:a:apache:tomcat:10.1.42
-
cpe:2.3:a:apache:tomcat:10.1.43
-
cpe:2.3:a:apache:tomcat:10.1.44
-
cpe:2.3:a:apache:tomcat:10.1.45
-
cpe:2.3:a:apache:tomcat:10.1.46
-
cpe:2.3:a:apache:tomcat:10.1.47
-
cpe:2.3:a:apache:tomcat:10.1.48
-
cpe:2.3:a:apache:tomcat:10.1.5
-
cpe:2.3:a:apache:tomcat:10.1.6
-
cpe:2.3:a:apache:tomcat:10.1.7
-
cpe:2.3:a:apache:tomcat:10.1.8
-
cpe:2.3:a:apache:tomcat:10.1.9
-
cpe:2.3:a:apache:tomcat:11.0.0
-
cpe:2.3:a:apache:tomcat:11.0.1
-
cpe:2.3:a:apache:tomcat:11.0.10
-
cpe:2.3:a:apache:tomcat:11.0.11
-
cpe:2.3:a:apache:tomcat:11.0.12
-
cpe:2.3:a:apache:tomcat:11.0.13
-
cpe:2.3:a:apache:tomcat:11.0.2
-
cpe:2.3:a:apache:tomcat:11.0.3
-
cpe:2.3:a:apache:tomcat:11.0.4
-
cpe:2.3:a:apache:tomcat:11.0.5
-
cpe:2.3:a:apache:tomcat:11.0.6
-
cpe:2.3:a:apache:tomcat:11.0.7
-
cpe:2.3:a:apache:tomcat:11.0.8
-
cpe:2.3:a:apache:tomcat:11.0.9
-
cpe:2.3:a:apache:tomcat:9.0.100
-
cpe:2.3:a:apache:tomcat:9.0.101
-
cpe:2.3:a:apache:tomcat:9.0.102
-
cpe:2.3:a:apache:tomcat:9.0.103
-
cpe:2.3:a:apache:tomcat:9.0.104
-
cpe:2.3:a:apache:tomcat:9.0.105
-
cpe:2.3:a:apache:tomcat:9.0.106
-
cpe:2.3:a:apache:tomcat:9.0.107
-
cpe:2.3:a:apache:tomcat:9.0.108
-
cpe:2.3:a:apache:tomcat:9.0.109
-
cpe:2.3:a:apache:tomcat:9.0.110
-
cpe:2.3:a:apache:tomcat:9.0.111
-
cpe:2.3:a:apache:tomcat:9.0.112
-
cpe:2.3:a:apache:tomcat:9.0.113
-
cpe:2.3:a:apache:tomcat:9.0.114
-
cpe:2.3:a:apache:tomcat:9.0.115
-
cpe:2.3:a:apache:tomcat:9.0.83
-
cpe:2.3:a:apache:tomcat:9.0.84
-
cpe:2.3:a:apache:tomcat:9.0.85
-
cpe:2.3:a:apache:tomcat:9.0.86
-
cpe:2.3:a:apache:tomcat:9.0.87
-
cpe:2.3:a:apache:tomcat:9.0.88
-
cpe:2.3:a:apache:tomcat:9.0.89
-
cpe:2.3:a:apache:tomcat:9.0.90
-
cpe:2.3:a:apache:tomcat:9.0.91
-
cpe:2.3:a:apache:tomcat:9.0.92
-
cpe:2.3:a:apache:tomcat:9.0.93
-
cpe:2.3:a:apache:tomcat:9.0.94
-
cpe:2.3:a:apache:tomcat:9.0.95
-
cpe:2.3:a:apache:tomcat:9.0.96
-
cpe:2.3:a:apache:tomcat:9.0.97
-
cpe:2.3:a:apache:tomcat:9.0.98
-
cpe:2.3:a:apache:tomcat:9.0.99
-
cpe:2.3:a:apache:tomcat_native:1.1.23
-
cpe:2.3:a:apache:tomcat_native:1.1.24
-
cpe:2.3:a:apache:tomcat_native:1.1.25
-
cpe:2.3:a:apache:tomcat_native:1.1.26
-
cpe:2.3:a:apache:tomcat_native:1.1.27
-
cpe:2.3:a:apache:tomcat_native:1.1.28
-
cpe:2.3:a:apache:tomcat_native:1.1.29
-
cpe:2.3:a:apache:tomcat_native:1.1.30
-
cpe:2.3:a:apache:tomcat_native:1.1.31
-
cpe:2.3:a:apache:tomcat_native:1.1.32
-
cpe:2.3:a:apache:tomcat_native:1.1.33
-
cpe:2.3:a:apache:tomcat_native:1.1.34
-
cpe:2.3:a:apache:tomcat_native:1.2.0
-
cpe:2.3:a:apache:tomcat_native:1.2.1
-
cpe:2.3:a:apache:tomcat_native:1.2.10
-
cpe:2.3:a:apache:tomcat_native:1.2.11
-
cpe:2.3:a:apache:tomcat_native:1.2.12
-
cpe:2.3:a:apache:tomcat_native:1.2.13
-
cpe:2.3:a:apache:tomcat_native:1.2.14
-
cpe:2.3:a:apache:tomcat_native:1.2.15
-
cpe:2.3:a:apache:tomcat_native:1.2.16
-
cpe:2.3:a:apache:tomcat_native:1.2.17
-
cpe:2.3:a:apache:tomcat_native:1.2.18
-
cpe:2.3:a:apache:tomcat_native:1.2.19
-
cpe:2.3:a:apache:tomcat_native:1.2.2
-
cpe:2.3:a:apache:tomcat_native:1.2.20
-
cpe:2.3:a:apache:tomcat_native:1.2.21
-
cpe:2.3:a:apache:tomcat_native:1.2.22
-
cpe:2.3:a:apache:tomcat_native:1.2.23
-
cpe:2.3:a:apache:tomcat_native:1.2.24
-
cpe:2.3:a:apache:tomcat_native:1.2.25
-
cpe:2.3:a:apache:tomcat_native:1.2.26
-
cpe:2.3:a:apache:tomcat_native:1.2.27
-
cpe:2.3:a:apache:tomcat_native:1.2.28
-
cpe:2.3:a:apache:tomcat_native:1.2.29
-
cpe:2.3:a:apache:tomcat_native:1.2.3
-
cpe:2.3:a:apache:tomcat_native:1.2.30
-
cpe:2.3:a:apache:tomcat_native:1.2.31
-
cpe:2.3:a:apache:tomcat_native:1.2.32
-
cpe:2.3:a:apache:tomcat_native:1.2.33
-
cpe:2.3:a:apache:tomcat_native:1.2.34
-
cpe:2.3:a:apache:tomcat_native:1.2.35
-
cpe:2.3:a:apache:tomcat_native:1.2.36
-
cpe:2.3:a:apache:tomcat_native:1.2.37
-
cpe:2.3:a:apache:tomcat_native:1.2.38
-
cpe:2.3:a:apache:tomcat_native:1.2.39
-
cpe:2.3:a:apache:tomcat_native:1.2.4
-
cpe:2.3:a:apache:tomcat_native:1.2.5
-
cpe:2.3:a:apache:tomcat_native:1.2.6
-
cpe:2.3:a:apache:tomcat_native:1.2.7
-
cpe:2.3:a:apache:tomcat_native:1.2.8
-
cpe:2.3:a:apache:tomcat_native:1.2.9
-
cpe:2.3:a:apache:tomcat_native:1.3.0
-
cpe:2.3:a:apache:tomcat_native:1.3.1
-
cpe:2.3:a:apache:tomcat_native:1.3.2
-
cpe:2.3:a:apache:tomcat_native:1.3.3
-
cpe:2.3:a:apache:tomcat_native:1.3.4
-
cpe:2.3:a:apache:tomcat_native:1.3.5
-
cpe:2.3:a:apache:tomcat_native:1.3.6
-
cpe:2.3:a:apache:tomcat_native:2.0.0
-
cpe:2.3:a:apache:tomcat_native:2.0.1
-
cpe:2.3:a:apache:tomcat_native:2.0.10
-
cpe:2.3:a:apache:tomcat_native:2.0.11
-
cpe:2.3:a:apache:tomcat_native:2.0.12
-
cpe:2.3:a:apache:tomcat_native:2.0.13
-
cpe:2.3:a:apache:tomcat_native:2.0.2
-
cpe:2.3:a:apache:tomcat_native:2.0.3
-
cpe:2.3:a:apache:tomcat_native:2.0.4
-
cpe:2.3:a:apache:tomcat_native:2.0.5
-
cpe:2.3:a:apache:tomcat_native:2.0.6
-
cpe:2.3:a:apache:tomcat_native:2.0.7
-
cpe:2.3:a:apache:tomcat_native:2.0.8
-
cpe:2.3:a:apache:tomcat_native:2.0.9