Detects Apache Tomcat versions 9.0.83–9.0.115, 10.1.0-M7–10.1.52, and 11.0.0-M1–11.0.18 where the FFM (Foreign Function & Memory) OpenSSL integration fails to set an X509 verification error when the OCSP responder returns TRY_LATER. On servers configured with CLIENT_CERT mutual TLS authentication and OCSP revocation checking with soft-fail disabled, an attacker with a revoked or unverifiable client certificate can bypass the revocation check and authenticate as if their certificate were valid. The fix in 9.0.116/10.1.53/11.0.20 adds X509_STORE_CTX_set_error to correctly reject the connection.
Is your app exploitable through CVE-2026-29145?
Scan your domain free