CVE-2026-24734 | Apache Tomcat up to 9.0.114/10.1.51/11.0.17 OCSP Certificate certificate validation (WID-SEC-2026-0443)
A vulnerability described as critical has been identified in Apache Tomcat up to 9.0.114/10.1.51/11.0.17. Affected by this issue is some unknown functionality of the component OCSP Certificate Handler. Such manipulation leads to improper certificate validation. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is listed as CVE-2026-24734. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.