CVE-2026-73581
Received
Received - Intake
Improper Certificate Revocation Check in Apache Tomcat
Vulnerability report for CVE-2026-73581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-23
Last updated on: 2026-09-23
Assigner: Apache Software Foundation
Description
Description
Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.58, from 9.0.0-M1 through 9.0.121.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100.Β Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.26, 10.1.59, 9.0.122, which fixes the issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | tomcat | From 11.0.0-M1 (inc) to 11.0.25 (inc) |
| apache | tomcat | From 10.1.0-M1 (inc) to 10.1.58 (inc) |
| apache | tomcat | From 9.0.0-M1 (inc) to 9.0.121 (inc) |
| apache | tomcat | From 8.5.0 (inc) to 8.5.100 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-299 | The product does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised. |