CVE-2026-53434

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

History

02 Jul 2026, 19:06

Type Values Removed Values Added
References () https://lists.apache.org/thread/x510lbq0sfrd1qyo7q3r1mpllgpdcosk - () https://lists.apache.org/thread/x510lbq0sfrd1qyo7q3r1mpllgpdcosk - Vendor Advisory, Mailing List
References () http://www.openwall.com/lists/oss-security/2026/06/29/22 - () http://www.openwall.com/lists/oss-security/2026/06/29/22 - Third Party Advisory
CPE cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
First Time Apache tomcat
Apache

30 Jun 2026, 13:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

29 Jun 2026, 23:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/06/29/22 -

29 Jun 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-29 21:16

Updated : 2026-07-02 19:06


NVD link : CVE-2026-53434

Mitre link : CVE-2026-53434

CVE.ORG link : CVE-2026-53434


JSON object : View

Products Affected

apache

  • tomcat
CWE
CWE-390

Detection of Error Condition Without Action