ghsa-c47j-g3rg-hrfq

github
Description

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [],
  "aliases": [
    "CVE-2026-86248"
  ],
  "database_specific": {
    "cwe_ids": [],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-23T12:17:08Z",
    "severity": null
  },
  "details": "CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121.\n\n\n\nUsers are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.",
  "id": "GHSA-c47j-g3rg-hrfq",
  "modified": "2026-09-23T12:31:16Z",
  "published": "2026-09-23T12:31:16Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86248"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}
View JSON API Download JSON