CVE-2026-73581
Publication date 24 September 2026
Last updated 24 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.58, from 9.0.0-M1 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.59, 9.0.122, which fixes the issue.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| tomcat6 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Needs evaluation
|
|
| tomcat7 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
|
| tomcat8 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| tomcat9 | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| tomcat10 | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy | Not in release | |
| tomcat11 | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release |
Notes
ebarretto
xenial tomcat6 only builds libservlet2.5-java, not the Tomcat server binaries bionic tomcat7 only builds libservlet3.0-java, not the Tomcat server binaries xenial tomcat6 only builds libservlet2.5-java, not the Tomcat server binaries bionic tomcat7 only builds libservlet3.0-java, not the Tomcat server binaries xenial tomcat6 only builds libservlet2.5-java, not the Tomcat server binaries bionic tomcat7 only builds libservlet3.0-java, not the Tomcat server binaries
Severity score breakdown
CVSS version: CVSS v3.0
Base score
6.5 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-73581
- https://github.com/apache/tomcat/commit/15a76156ced9f6a6306ef7d6f2e343034231a2de (11.0.26)
- https://github.com/apache/tomcat/commit/6907d47ea2d4c3f13ef9f65b0c51ff2fd485c252 (10.1.60)
- https://github.com/apache/tomcat/commit/2dce8f26b3ba6a89c8f172b94fa41a5fa2dcc361 (9.0.122)
- https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do
- http://www.openwall.com/lists/oss-security/2026/09/23/19