CVE-2026-86350

EUVD-2026-85235
Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up.



This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121.



Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
HTTP Request/Response Smuggling
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
apacheCNA
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
apachetomcat
11.0.22 ≤
𝑥
≤ 11.0.25
CNA
apachetomcat
10.1.55 ≤
𝑥
≤ 10.1.59
CNA
apachetomcat
9.0.118 ≤
𝑥
≤ 9.0.121
CNA
Debian logo
Debian Releases
Debian Product
Codename
tomcat10
bookworm
vulnerable
bookworm (security)
vulnerable
forky
vulnerable
sid
10.1.60-1
fixed
trixie
vulnerable
trixie (security)
vulnerable
tomcat11
forky
vulnerable
sid
vulnerable
trixie
vulnerable
trixie (security)
vulnerable
tomcat9
bookworm
9.0.70-2
fixed
forky
9.0.118-1
fixed
sid
9.0.122-1
fixed
trixie
9.0.95-1
fixed