https://seclists.org/oss-sec/2026/q3/905: CVE-2026-78437: Apache Tomcat: HTTP/2 DoS via malformed quest
Published Sep 23, 2026
·Updated
Affected Software
1 affected component
Apache Tomcat>=11.0.19<=11.0.25, >=10.1.53<=10.1.59, >=9.0.116<=9.0.121
Apache Tomcat 8.5 through 8.5.100 is listed as unaffected.
Affected versions are Tomcat 11.0.19 through 11.0.25, 10.1.53 through 10.1.59, and 9.0.116 through 9.0.121. The provided data does not state the status of versions outside these ranges.