All verified exploits

CVE-2026-29145 OCSP Revocation Bypass via FFM OpenSSL TRY_LATER Handling

Pentest high Apache Tomcat Added cve-verified-cve-2026-29145

Detects Apache Tomcat versions 9.0.83–9.0.115, 10.1.0-M7–10.1.52, and 11.0.0-M1–11.0.18 where the FFM (Foreign Function & Memory) OpenSSL integration fails to set an X509 verification error when the OCSP responder returns TRY_LATER. On servers configured with CLIENT_CERT mutual TLS authentication and OCSP revocation checking with soft-fail disabled, an attacker with a revoked or unverifiable client certificate can bypass the revocation check and authenticate as if their certificate were valid. The fix in 9.0.116/10.1.53/11.0.20 adds X509_STORE_CTX_set_error to correctly reject the connection.

Is your app exploitable through CVE-2026-29145?

Scan your domain free