Apache Tomcat 11.0.26 Patches HTTP/2 Race Condition That Leaks Request Trailers
Apache Tomcat has released version 11.0.26, fixing CVE-2026-77762, a race condition in which a stale HPACK emitter can inject trailer fields from one HTTP/2 request into another recycled request object. The flaw affects Tomcat versions 11.0.0-M1 through 11.0.25, and was privately reported to the Apache security team on 21 August 2026 before being made public on 23 September 2026. Apache rates the vulnerability Low, though a third-party CVSS score of 8.1 has been assigned under CWE-362, creating a notable gap in severity assessments. The practical risk depends on how an application handles trailers — services using them for signatures, routing, or metadata are more exposed, while those that ignore trailers are unlikely to be affected. No configuration-based workaround exists; upgrading to Tomcat 11.0.26, which also addresses four other vulnerabilities in the same release, is the only recommended fix.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in