Emerging Threat: (CVE-2026-29145) Apache Tomcat CLIENT_CERT Authentication Bypass via OCSP Soft-Fail
An authentication bypass vulnerability in Apache Tomcat and Tomcat Native can allow unauthorized access to CLIENT_CERT-protected resources when OCSP soft-fail is disabled, bypassing the mutual TLS access control that the certificate validation policy was intended to enforce.
Read more about Emerging Threat: (CVE-2026-29145) Apache Tomcat CLIENT_CERT Authentication Bypass via OCSP Soft-Fail