← Back to search

CVE-2026-86350

9.1 CRITICAL

Published 2026-09-23 · Updated 2026-09-23

AI risk analysis

Summary
This flaw involves an inconsistent interpretation of HTTP/2 requests, leading to potential request header mix-ups, which can be exploited to manipulate HTTP requests and responses.
Exploitability
Exploitation is moderately difficult and requires the attacker to send specific HTTP/2 requests that trigger the vulnerability. Precondition is the presence of affected Apache Tomcat versions.
Blast radius
If exploited, this could lead to unauthorized access or manipulation of HTTP requests and responses, potentially leading to data leakage or other security breaches.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Apache Tomcat version 11.0.26, 10.1.60, or 9.0.122.
http2tomcatrequest-mix-uphttp-requestsecurity-flaw

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-444

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.