Inconsistent interpretation of HTTP requests in Apache Tomcat - CVE-2026-86350
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a request header mix-up.
The vulnerability exists due to inconsistent interpretation of HTTP/2 requests in HTTP/2 request processing when handling HTTP/2 requests. A remote attacker can send a crafted HTTP/2 request to cause a request header mix-up.
The issue is a regression in the fix for CVE-2026-41293.