CVE-2026-86350
9.1 CRITICALPublished 2026-09-23 · Updated 2026-09-23
AI risk analysis
- Summary
- This flaw involves an inconsistent interpretation of HTTP/2 requests, leading to potential request header mix-ups, which can be exploited to manipulate HTTP requests and responses.
- Exploitability
- Exploitation is moderately difficult and requires the attacker to send specific HTTP/2 requests that trigger the vulnerability. Precondition is the presence of affected Apache Tomcat versions.
- Blast radius
- If exploited, this could lead to unauthorized access or manipulation of HTTP requests and responses, potentially leading to data leakage or other security breaches.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Apache Tomcat version 11.0.26, 10.1.60, or 9.0.122.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-444
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-15314
- HIGHCVE-2026-56848
- HIGHCVE-2026-73513PoC
- HIGHCVE-2026-73550PoC
- CRITICALCVE-2026-76183
- MEDIUMCVE-2026-77519PoC
- CRITICALCVE-2026-86246
- CRITICALCVE-2026-86248
Related by shared AI tags and CWE weakness class. Browse the full archive.