Patch Matrix for CVE-2026-86350: Which Apache Tomcat Builds Need 11.0.26, 10.1.60 or 9.0.122
Patch Matrix for CVE-2026-86350: Which Apache Tomcat Builds Need 11.0.26, 10.1.60 or 9.0.122 Operator summary CVE-2026-86350 is an Important-severity Apache Tomcat defect involving a request header mix-up in HTTP/2 handling. It is a regression from the fix for CVE-2026-41293. Remediation is a version move, and the correct target depends on the branch a server runs. Branch Vulnerable range Fixed release Vendor commit Tomcat 11.0.x 11.0.22 to 11.0.25 11.0.26 192bc749 Tomcat 10.1.x 10.1.55 to 10.1.59 10.1.60 259e938d Tomcat 9.0.x 9.0.118 to 9.0.121 9.0.122 5adadc4e Tomcat 8.5 does not appear agai
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in