Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-29145-Tester β€” This repository contains a proof-of-concept (PoC) environment designed to test for CVE-2026-29145. | Kitploit
Tools/GitHubGitHub/chenjp/cve-2026-29145-tester
Vulnerability AnalysisExploitationWeb SecurityPenetration TestingAuthenticationLearning & Education
GitHubchenjp/cve-2026-29145-tester

CVE-2026-29145-Tester

This repository contains a proof-of-concept (PoC) environment designed to test for CVE-2026-29145.

View Repository
205 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

CVE-2026-29145 Testing Environment

πŸ“Œ Overview

This repository contains a proof-of-concept (PoC) environment designed to test for CVE-2026-29145.

The vulnerability is an authentication bypass in Apache Tomcat's Mutual TLS (CLIENT_CERT) implementation. When OCSP (Online Certificate Status Protocol) is configured with soft-fail disabled, Tomcat may fail to treat an OCSP check failure as a hard denial. This allows a client with a potentially revoked or unverified certificate to bypass authentication if the OCSP responder is unreachable or returns an error.

πŸ›‘οΈ Vulnerability Details

PropertyValue
CVE IDCVE-2026-29145
CVSS Score9.1 (Critical) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack VectorNetwork
Privileges RequiredNone
ImpactAuthentication Bypass

Prerequisites for Vulnerability

  • βœ“ CLIENT_CERT authentication enabled in Tomcat
  • βœ“ OCSP revocation checking enabled
  • βœ“ Soft-fail option disabled (hard-fail mode)
  • βœ“ Unreachable or failing OCSP responder

πŸš€ Getting Started

Prerequisites

  • Docker & Docker Compose: To run the vulnerable Tomcat container
  • OpenSSL: To generate the PKI (Public Key Infrastructure) - usually pre-installed on Linux/macOS
  • Python 3.7+: To run the testing script and mock responder
  • curl (optional): For manual testing
  • PowerShell (Windows only): If using the .ps1 scripts

1. Automated Full Test Cycle (Recommended)

The run_test.sh script automates the entire process: cleanup, certificate generation, and running all test scenarios (vulnerable, success, and patched).

# Navigate to the project directory
cd CVE-2026-29145-Tester

# Make scripts executable
chmod +x cleanup.sh setup_certs.sh run_test.sh

# Install Python dependencies (if poc_exploit.py requires them)
pip install -r requirements.txt

# Run the full test suite
./run_test.sh

2. Generate certificates

On Linux/macOS:

./setup_certs.sh

On Windows (PowerShell):

.\setup_certs.ps1

What this does:

  • Creates a Root CA (Certificate Authority)
  • Generates server certificate for Tomcat
  • Generates client certificate with OCSP extension pointing to http://localhost:8888
  • Validates all certificates were created successfully

Expected output:

[INFO] Starting certificate generation for CVE-2026-29145 testing environment
[INFO] OpenSSL found: OpenSSL 3.0.x (...)
[INFO] Created certs directory
[INFO] Generating Root CA...
[INFO] Generating Server Certificate...
[INFO] Generating Client Certificate with OCSP Extension...
[INFO] Certificate setup completed successfully!

3. Start the vulnerable environment

docker-compose up -d

What this does:

  • Starts the OCSP Mock Responder on port 8888 (simulates failure with HTTP 500)
  • Starts vulnerable Tomcat 10.1.52 on port 8443 with CLIENT_CERT authentication
  • Creates internal Docker network for service communication
  • Sets up health checks for both services

Verify containers are running:

docker-compose ps

4. Run the exploitation test

python poc_exploit.py

Expected outputs:

Vulnerable System:

[INFO] Attempting connection to https://localhost:8443/protected-resource...
[WARNING] VULNERABLE: Access granted despite OCSP check failure.
[WARNING] Response preview: <html>...

Patched System:

[INFO] Attempting connection to https://localhost:8443/protected-resource...
[INFO] NOT VULNERABLE: Access denied (Authentication working).

πŸ§ͺ Testing Scenarios

ScenarioOCSP StatusExpected (Patched)Result (Vulnerable)Notes
Normal OperationOnline & Valid200 OK βœ“200 OK βœ“OCSP check succeeds, access granted
Soft FailureOffline/Timeout403 Forbidden βœ“200 OK βœ—BYPASS - OCSP responder unreachable
Hard RevocationOnline & Revoked403 Forbidden βœ“403 Forbidden βœ“Certificate explicitly revoked
Invalid CertificateInvalid Chain403 Forbidden βœ“403 Forbidden βœ“Chain validation fails

Running Different Test Scenarios

Test 1: Default (OCSP Responder Failing)

# Keep containers running
python poc_exploit.py

Test 2: Stop OCSP Responder (Simulate Timeout)

docker-compose pause ocsp-responder
python poc_exploit.py
docker-compose unpause ocsp-responder

Test 3: Manual Testing with curl

curl -v \
  --cert certs/client-cert.pem \
  --key certs/client-key.pem \
  --cacert certs/ca-chain.pem \
  https://localhost:8443/protected-resource

πŸ› οΈ Project Structure

CVE-2026-29145-Tester/
β”œβ”€β”€ README.md                    # This file
β”œβ”€β”€ setup_certs.sh              # Certificate generation script - Bash (Linux/macOS)
β”œβ”€β”€ setup_certs.ps1             # Certificate generation script - PowerShell (Windows)
β”œβ”€β”€ cleanup.sh                  # Cleanup and reset script - Bash (Linux/macOS)
β”œβ”€β”€ cleanup.ps1                 # Cleanup and reset script - PowerShell (Windows)
β”œβ”€β”€ run_test.sh                 # Automated full test cycle script
β”œβ”€β”€ docker-compose.yml          # Docker service orchestration
β”œβ”€β”€ requirements.txt            # Python dependencies
β”œβ”€β”€ poc_exploit.py              # Main testing script (with logging and error handling)
β”œβ”€β”€ simple_proxy_fail.py        # Mock OCSP responder (with detailed logging)
β”œβ”€β”€ .gitignore                  # Git ignore rules for certificates and logs
β”œβ”€β”€ certs/                      # Generated certificates (created by setup_certs scripts)
β”‚   β”œβ”€β”€ ca-chain.pem           # Root CA certificate
β”‚   β”œβ”€β”€ ca-key.pem             # Root CA private key
β”‚   β”œβ”€β”€ server-cert.pem        # Tomcat server certificate
β”‚   β”œβ”€β”€ server-key.pem         # Tomcat server private key
β”‚   β”œβ”€β”€ client-cert.pem        # Test client certificate
β”‚   └── client-key.pem         # Test client private key
β”œβ”€β”€ tomcat/
β”‚   └── server.xml             # Vulnerable Tomcat configuration
└── logs/                       # Tomcat logs (created at runtime)

πŸ“‹ Configuration Details

Server.xml Configuration (Vulnerable)

The tomcat/server.xml file configures:

<SSLHostConfig 
    hostName="localhost"
    certificateVerification="required"
    caCertificateFile="conf/certs/ca-chain.pem">
    
    <OpenSSLConf>
        <ConfCommand name="OCSP" value="on"/>
    </OpenSSLConf>
</SSLHostConfig>

Key Settings:

  • certificateVerification="required" - Enforces CLIENT_CERT authentication
  • OCSP on - Enables OCSP revocation checking
  • No soft-fail override - Uses hard-fail mode (vulnerable)

OCSP Responder Configuration

The mock OCSP responder (simple_proxy_fail.py):

  • Listens on localhost:8888
  • Always returns HTTP 500 (Server Error)
  • Logs all incoming OCSP requests
  • Simulates an unreachable/failing OCSP service

πŸ”§ Troubleshooting

Common Issues & Solutions

❌ Error: "OpenSSL is not installed"

# macOS
brew install openssl

# Ubuntu/Debian
sudo apt-get install openssl

# CentOS/RHEL
sudo yum install openssl

❌ Error: "Missing certificate files"

Cause: Certificate generation failed or was not run.

# Clean up and regenerate
rm -rf certs
./setup_certs.sh

❌ Error: "Connection refused" on port 8443

Cause: Tomcat container is not running or not ready.

# Check container status
docker-compose ps

# Check logs
docker-compose logs vulnerable-tomcat

# Ensure both services are running and healthy
docker-compose up -d
sleep 10  # Wait for services to start

❌ Error: "Connection timeout"

Cause: Tomcat taking too long to start or network issues.

# Check Tomcat startup logs
docker-compose logs vulnerable-tomcat

# Increase timeout and retry
timeout 30 docker-compose logs -f vulnerable-tomcat  # Monitor startup
Download Tool