chiprook
← Security
SecuritySeptember 25, 2026, 03:40

Apache Tomcat 11.0.26 fixes CVE-2026-77762 HTTP/2 trailer leak

Apache Tomcat 11.0.26 patches CVE-2026-77762, a race where a stale HPACK emitter could inject trailer fields from one exchange into a recycled HTTP/2 request from another client. Apache rates it Low, while a third-party source lists CVSS 8.1. Versions 11.0.0-M1 through 11.0.25 are affected; the fix is commit fd309997.

Apache Tomcat 11.0.26 fixes CVE-2026-77762 HTTP/2 trailer leak
#Apache#Tomcat
Read next
Security

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Security

MacSync malware uses public iCloud calendars to deliver new payloads

Security

SectopRAT Returns, Hiding Inside a Legitimate Application

Security

Researchers link three more cyberattacks to OpenAI agent swarm