HTTP/2 Request Smuggling Vulnerability in Apache Tomcat
CVE-2026-86350

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-86350?

Inconsistent handling of HTTP/2 requests in Apache Tomcat can lead to request header mix-ups. This vulnerability arises from a regression in previous fixes and affects several versions of Tomcat, making systems potentially susceptible to exploitation. Users should promptly upgrade to the recommended versions to mitigate these risks.

Affected Version(s)

Apache Tomcat 11.0.22 <= 11.0.25

Apache Tomcat 10.1.55 <= 10.1.59

Apache Tomcat 9.0.118 <= 9.0.121

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeppe Weikop
.