Apache Tomcat 11.0.26 fixes HTTP/2 header mix-up regression CVE-2026-86350
Apache released Tomcat 11.0.26 with a fix for CVE-2026-86350, a regression in HTTP/2 handling that could attach request headers to a different client's exchange on the same connection. Affected branches are 11.0.22–11.0.25, 10.1.55–10.1.59 and 9.0.118–9.0.121; fixes ship in 11.0.26, 10.1.60 and 9.0.122.
- Regression came with the CVE-2026-41293 patch and persisted in 11.0.22–11.0.25
- Affected branches: 11.0.22–11.0.25, 10.1.55–10.1.59, 9.0.118–9.0.121
- Fixes: 11.0.26, 10.1.60 and 9.0.122; commits 192bc749, 259e938d, 5adadc4e
- ZoomEye: about 580,597 exposed Tomcat assets, but 0 hosts with CVE-2026-86350
Read next
Security