Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-86350: Apache Tomcat may mix up HTTP requests
CVE-2026-86350 · published 1 day ago
Summary
Certain versions of Apache Tomcat (11.0.22‑11.0.25, 10.1.55‑10.1.59, 9.0.118‑9.0.121) can confuse the boundaries between separate web requests, allowing a malicious user to sneak extra data into another request. This could let an attacker bypass security checks or cause unintended actions on your site. Upgrade to Tomcat 11.0.26, 10.1.60 or 9.0.122, or apply the latest security updates from your Linux distribution.
What to do
- Update debian tomcat9 to version 9.0.70-2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | apache software foundation | apache tomcat | <= 11.0.25 |
| Debian:13 | debian | tomcat11 | All versions |
| Debian:12 | debian | tomcat10 | All versions |
| Debian:12 | debian | tomcat9 |
< 9.0.70-2 Fix: upgrade to 9.0.70-2
|
| Ubuntu:Pro:14.04:LTS | canonical | tomcat7 | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | tomcat8 | All versions |
| Ubuntu:Pro:14.04:LTS | canonical | tomcat6 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | tomcat9 | All versions |
| Ubuntu:24.04:LTS | canonical | tomcat10 | All versions |
| Ubuntu:26.04:LTS | canonical | tomcat11 | All versions |
Original advisory text
DEBIAN-CVE-2026-86350
Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
References
- https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-86350 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-86350 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-86350 Third Party Advisory
- https://github.com/apache/tomcat/commit/192bc74996e1ad35d79118f750574d366bd43cea Third Party Advisory
- https://github.com/apache/tomcat/commit/259e938d3dedf07f3b24189fd5032adb95b01f2a Third Party Advisory
- https://github.com/apache/tomcat/commit/5adadc4ef413d5050f664d40800bbff74bd5d5ed Third Party Advisory
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Timeline
Published24 Sep 2026
Updated25 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-86350 · NVD
CVE-2026-86350 · MITRE
DEBIAN-CVE-2026-86350 · OSV
UBUNTU-CVE-2026-86350 · OSV
Track software like this
Free during beta