CVE-2026-86350: Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up
A Tomcat regression of the CVE-2026-41293 fix can mix HTTP/2 request headers.
Apache Tomcat CVE-2026-86350 is an important-severity HTTP/2 request-smuggling flaw caused by a regression in the fix for CVE-2026-41293. Inconsistent interpretation of HTTP/2 requests can mix up request headers. Affected versions are Tomcat 11.0.22 through 11.0.25, 10.1.55 through 10.1.59, and 9.0.118 through 9.0.121. The oss-security post does not say the flaw is being exploited.
- Regression affects recent Tomcat 9, 10.1, and 11 releases.
- Apache rates the HTTP/2 header mix-up as important.
- Issue stems from the CVE-2026-41293 fix; exploitation is unreported.
Vulnerabilities mentionedAll →
- CVE-2026-412939.82%Improper Input Validation vulnerability in Apache Tomcatpublished · apache tomcat
- CVE-2026-863509.1—HTTP/2 Request Smuggling Regression in Apache Tomcat 9, 10.1 and 11published · Apache Tomcat
Posted by Mark Thomas on Sep 23 Severity: important Affected versions: - Apache Tomcat 11.0.22 through 11.0.25 - Apache Tomcat 10.1.55 through 10.1.59 - Apache Tomcat 9.0.118 through 9.0.121 Description: Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25,...
This source does not provide full text. Read it at seclists.org.