Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-86350: Apache Tomcat may mix up HTTP requests

CVE-2026-86350 · published 1 day ago
Summary

Certain versions of Apache Tomcat (11.0.22‑11.0.25, 10.1.55‑10.1.59, 9.0.118‑9.0.121) can confuse the boundaries between separate web requests, allowing a malicious user to sneak extra data into another request. This could let an attacker bypass security checks or cause unintended actions on your site. Upgrade to Tomcat 11.0.26, 10.1.60 or 9.0.122, or apply the latest security updates from your Linux distribution.

What to do
  • Update debian tomcat9 to version 9.0.70-2.
Affected software
Ecosystem VendorProductAffected versions
– apache software foundation apache tomcat <= 11.0.25
Debian:13 debian tomcat11 All versions
Debian:12 debian tomcat10 All versions
Debian:12 debian tomcat9 < 9.0.70-2
Fix: upgrade to 9.0.70-2
Ubuntu:Pro:14.04:LTS canonical tomcat7 All versions
Ubuntu:Pro:16.04:LTS canonical tomcat8 All versions
Ubuntu:Pro:14.04:LTS canonical tomcat6 All versions
Ubuntu:Pro:18.04:LTS canonical tomcat9 All versions
Ubuntu:24.04:LTS canonical tomcat10 All versions
Ubuntu:26.04:LTS canonical tomcat11 All versions
Original advisory text
DEBIAN-CVE-2026-86350
Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Timeline
Published24 Sep 2026
Updated25 Sep 2026
First seen23 Sep 2026
Track software like this
Free during beta