Race Condition Vulnerability in Apache Tomcat
CVE-2026-77762

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-77762?

A race condition vulnerability in Apache Tomcat allows attackers to exploit improper synchronization, enabling the injection of trailer fields into another HTTP/2 request. This can lead to unauthorized data manipulation and security breaches. Versions 11.0.0-M1 through 11.0.25, 10.1.0-M1 through 10.1.59, and 9.0.39 through 9.0.121 are affected, along with unsupported versions 8.5.59 through 8.5.100. Users should promptly upgrade to patched versions to mitigate risks.

Affected Version(s)

Apache Tomcat 11.0.0-M1 <= 11.0.25

Apache Tomcat 10.1.0-M1 <= 10.1.59

Apache Tomcat 9.0.39 <= 9.0.121

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.