Apache Tomcat Patches HTTP/2 Header Mix-Up Bug Affecting Three Release Branches
Apache released Tomcat 11.0.26 on September 15, 2026, addressing CVE-2026-86350, a regression introduced while fixing an earlier HTTP/2 vulnerability, CVE-2026-41293. The flaw affects Tomcat versions 11.0.22–11.0.25, 10.1.55–10.1.59, and 9.0.118–9.0.121, where the HTTP/2 connector can incorrectly attribute request headers to the wrong client on a shared connection. This mismatch can cause cached responses to reach unintended recipients and may cause security rules such as routing or rate limiting to be applied against incorrect request data. Apache has issued fixes across all three branches, with users advised to upgrade to versions 11.0.26, 10.1.60, or 9.0.122 respectively. No active exploitation has been confirmed, but administrators unable to upgrade immediately are encouraged to disable HTTP/2 on the connector as a temporary mitigation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in