
Original security research and proof-of-concept for CVE-2026-29145, an Apache Tomcat OCSP authentication bypass vulnerability, including technical analysis and reproduction steps.
Discoverer: gregk4sec (https://github.com/gregk4sec/cve)
Discovery Date: 2026-02-26
Affected Vendor: Apache
Affected Product: Tomcat
Severity: 9.1 CRITICAL
CWE: CWE-287 Improper Authentication
Status: Under Review / Fixed / Private / Public ✅
CLIENT_CERT authentication did not fail OCSP checks as expected for some scenarios when soft fail was disabled.
See:
PoC files are located in:
./poc/
Note: Some PoC content may be redacted or published later depending on disclosure requirements.
See: timeline.md
See: ./vendor-response/
This vulnerability is an original discovery by gregk4sec (https://github.com/gregk4sec/cve).
Repository: https://github.com/gregk4sec/cve