chiprook
← Security
SecuritySeptember 26, 2026, 12:20

Apache Tomcat 11.0.26 fixes HTTP/2 header mix-up regression CVE-2026-86350

Apache released Tomcat 11.0.26 with a fix for CVE-2026-86350, a regression in HTTP/2 handling that could attach request headers to a different client's exchange on the same connection. Affected branches are 11.0.22–11.0.25, 10.1.55–10.1.59 and 9.0.118–9.0.121; fixes ship in 11.0.26, 10.1.60 and 9.0.122.

Apache Tomcat 11.0.26 fixes HTTP/2 header mix-up regression CVE-2026-86350
#Apache#Tomcat
Read next
Security

CVE-2026-48710 (BadHost): malformed Host header bypasses Starlette path authorization

Security

ZoomEye finds 73,105 exposed Airflow, 11,673 SonarQube and 33,837 Nexus instances

Software

Lyft Moves Streaming Fleet to Apache Flink Kubernetes Operator

Security

ACSC warns of widespread credential-based attacks on FortiGate gateways