{"id":"CVE-2026-86350","published":"2026-09-23T12:17:08.350","lastModified":"2026-09-23T17:58:26.570","description":"Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121.\n\n\n\nUsers are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-444"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw involves an inconsistent interpretation of HTTP/2 requests, leading to potential request header mix-ups, which can be exploited to manipulate HTTP requests and responses.","exploitability":"Exploitation is moderately difficult and requires the attacker to send specific HTTP/2 requests that trigger the vulnerability. Precondition is the presence of affected Apache Tomcat versions.","blast_radius":"If exploited, this could lead to unauthorized access or manipulation of HTTP requests and responses, potentially leading to data leakage or other security breaches.","remediation":"Upgrade to Apache Tomcat version 11.0.26, 10.1.60, or 9.0.122.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["http2","tomcat","request-mix-up","http-request","security-flaw"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:51:58.210Z"}}