chiprook
← Security
SecurityOctober 1, 2026, 15:20

CVE-2026-77762 in Apache Tomcat: vendor rates Low, third parties 8.1

A race condition (CWE-362) in Apache Tomcat 11.0.0-M1 through 11.0.25 lets an attacker inject trailer fields into another HTTP/2 request. Apache rates it Low while third-party sources list CVSS 8.1; the fix ships in Tomcat 11.0.26 (commit fd309997).

CVE-2026-77762 in Apache Tomcat: vendor rates Low, third parties 8.1
#Apache#Tomcat
Read next
Security

Apache Tomcat 11.0.26 fixes CVE-2026-77762 HTTP/2 trailer leak

Security

Bitget says attacker stole $388M via third-party security flaw

Security

Report: 48% of 2026 breaches involve third parties

Security

Third-party cyber breaches hit South African firms