---
id: CVE-2026-53434
title: >-
  Detection of Error Condition Without Action vulnerability in Apache Tomcat
  when configuring CRLs for a FFM based connector.


  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from
  10.1.0-M7 through 10.1.55, from 9.0.83 th…
summary: >-
  Detection of Error Condition Without Action vulnerability in Apache Tomcat
  when configuring CRLs for a FFM based connector.


  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from
  10.1.0-M7 through 10.1.55, from 9.0.83 th…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-390
vendor: apache
product: tomcat
affected:
  - 'tomcat >= 9.0.83, < 9.0.119'
  - 'tomcat >= 10.1.0, < 10.1.56'
  - 'tomcat >= 11.0.0, < 11.0.23'
patched:
  - tomcat 11.0.23
published: '2026-06-29'
updated: '2026-07-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53434'
references:
  - url: 'https://lists.apache.org/thread/x510lbq0sfrd1qyo7q3r1mpllgpdcosk'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/06/29/22'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53434.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-53434'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2494668'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-53434'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53434'
  - url: 'https://access.redhat.com/errata/RHSA-2026:49951'
  - url: 'https://access.redhat.com/errata/RHSA-2026:29203'
  - url: 'https://access.redhat.com/errata/RHSA-2026:32960'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - score-dispute
epss: 0.00597
epssPercentile: 0.46219
ingestedAt: '2026-07-03T13:02:28.101Z'
scores:
  nvd: 9.1
  vendor: 3.7
---

## Overview

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.

Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

## Affected

- `tomcat >= 9.0.83, < 9.0.119`
- `tomcat >= 10.1.0, < 10.1.56`
- `tomcat >= 11.0.0, < 11.0.23`

## Remediation

Upgrade past the affected range:

- `tomcat 11.0.23`

## Vendor advisories

- **RHSA-2026:49951** · Red Hat · fixed in: Red Hat JBoss Web Server 7.0 on RHEL 10, Red Hat JBoss Web Server 7.0 on RHEL 8, Red Hat JBoss Web Server 7.0 on RHEL 9 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:49951)
- **RHSA-2026:29203** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:29203)
- **RHSA-2026:32960** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:32960)
- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat JBoss Web Server 5, … · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53434.json)
