CVE-2026-86350: Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up
Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up.
This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121.
Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.26 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.60 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.122
Event History
Frequently Asked Questions
Which Tomcat release lines are affected, and what versions fix the issue?
Affected versions are 11.0.22 through 11.0.25, 10.1.55 through 10.1.59, and 9.0.118 through 9.0.121. Upgrade to 11.0.26, 10.1.60, or 9.0.122 respectively.
How can I determine whether an instance needs remediation?
Check the running Apache Tomcat version. Instances in any of the affected version ranges should be treated as affected and upgraded to the corresponding fixed release.