HTTP Request/Response Smuggling Vulnerability in Apache Tomcat
CVE-2026-77756

3.7LOW

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-77756?

A vulnerability exists in Apache Tomcat due to inconsistent interpretation of the transfer-encoding header for HTTP/1.0 requests. This flaw may allow attackers to interfere with requests made by other users when Tomcat is positioned behind a reverse proxy. Affected versions include multiple releases across the Tomcat 11, 10, 9, and 8.5 tracks. It is critical for users to upgrade to the latest secure versions to mitigate potential security risks.

Affected Version(s)

Apache Tomcat 11.0.0-M1 <= 11.0.25

Apache Tomcat 10.1.0-M1 <= 10.1.59

Apache Tomcat 9.0.47 <= 9.0.121

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.