Apache Tomcat 11.0.26 fixes CVE-2026-77762 HTTP/2 trailer leak
Apache Tomcat 11.0.26 patches CVE-2026-77762, a race where a stale HPACK emitter could inject trailer fields from one exchange into a recycled HTTP/2 request from another client. Apache rates it Low, while a third-party source lists CVSS 8.1. Versions 11.0.0-M1 through 11.0.25 are affected; the fix is commit fd309997.
- Tomcat 11.0.0-M1–11.0.25 affected, fixed in 11.0.26
- Apache rates it Low; third-party score is CVSS 8.1 (CWE-362)
- Issue became public on 23 September 2026; fix is commit fd309997
- 11.0.26 also fixes CVE-2026-86350, CVE-2026-78383, CVE-2026-87022 and CVE-2026-77791
Read next
Security