CVE-2026-77762 in Apache Tomcat: vendor rates Low, third parties 8.1
A race condition (CWE-362) in Apache Tomcat 11.0.0-M1 through 11.0.25 lets an attacker inject trailer fields into another HTTP/2 request. Apache rates it Low while third-party sources list CVSS 8.1; the fix ships in Tomcat 11.0.26 (commit fd309997).
- Affected: Apache Tomcat 11.0.0-M1 through 11.0.25; fixed in 11.0.26
- Apache rates it Low; third-party sources list CVSS 8.1 and CWE-362
- High risk only if the application reads HTTP/2 trailer fields
- ZoomEye: 580,597 instances of app="Apache Tomcat", zero CVE matches
Read next
Security