CVE-2026-86350: CWE-444 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') in Apache Software Foundation Apache Tomcat
Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
AI Analysis
Technical Summary
CVE-2026-86350 is a security vulnerability in Apache Tomcat where inconsistent interpretation of HTTP/2 requests can cause HTTP Request/Response smuggling due to a regression in the fix for CVE-2026-41293. This results in request header mix-ups that may impact the integrity of HTTP communications. The vulnerability affects multiple Apache Tomcat branches: 9.0.118 to 9.0.121, 10.1.55 to 10.1.59, and 11.0.22 to 11.0.25. The issue is resolved in versions 9.0.122, 10.1.60, and 11.0.26.
Potential Impact
The vulnerability allows inconsistent parsing of HTTP/2 requests, which can lead to HTTP Request/Response smuggling attacks. This can cause request header mix-ups, potentially impacting the security and reliability of HTTP communications handled by affected Apache Tomcat servers. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Users should upgrade affected Apache Tomcat versions to 9.0.122, 10.1.60, or 11.0.26, where the vulnerability has been fixed. Applying these official updates is the recommended remediation.
CVE-2026-86350: CWE-444 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') in Apache Software Foundation Apache Tomcat
Description
Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
CVSS v3.1
Score 9.1critical
Affected software
Apache Software Foundation
Apache Tomcat
pkg:maven/org.apache.tomcat/tomcatRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-86350 is a security vulnerability in Apache Tomcat where inconsistent interpretation of HTTP/2 requests can cause HTTP Request/Response smuggling due to a regression in the fix for CVE-2026-41293. This results in request header mix-ups that may impact the integrity of HTTP communications. The vulnerability affects multiple Apache Tomcat branches: 9.0.118 to 9.0.121, 10.1.55 to 10.1.59, and 11.0.22 to 11.0.25. The issue is resolved in versions 9.0.122, 10.1.60, and 11.0.26.
Potential Impact
The vulnerability allows inconsistent parsing of HTTP/2 requests, which can lead to HTTP Request/Response smuggling attacks. This can cause request header mix-ups, potentially impacting the security and reliability of HTTP communications handled by affected Apache Tomcat servers. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Users should upgrade affected Apache Tomcat versions to 9.0.122, 10.1.60, or 11.0.26, where the vulnerability has been fixed. Applying these official updates is the recommended remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-09-07T09:49:48.382Z
- State
- PUBLISHED
Threat ID: 6ab3bc94f7a7c54106b7b02a
Added to database: 09/23/2026, 11:48:36 UTC
Last enriched: 09/23/2026, 12:02:58 UTC
Last updated: 09/24/2026, 03:22:47 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.