• PoC PUBLIC

CVE-2026-86350: remote request smuggling in Apache Software Foundation Apache Tomcat

Unauthenticated remote attackers can exploit an HTTP/2 parsing regression in Apache Tomcat to confuse how the server separates and forwards client requests, potentially allowing one client's request data to be mixed with another's and leading to high-impact request handling errors; this is tracked as CVE-2026-86350. Affected releases include Tomcat 11.0.22–11.0.25, 10.1.55–10.1.59, and 9.0.118–9.0.121. Exploitation requires only network access to a Tomcat HTTP/2 endpoint—no credentials or user interaction are needed.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.1CRITICAL
EPSS
0.00313
CWE
CWE-444
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: public exploit code exists and the flaw can be triggered without authentication, so immediately limit exposure and follow vendor mitigation guidance.

What is CVE-2026-86350?

Unauthenticated remote attackers can exploit an HTTP/2 parsing regression in Apache Tomcat to confuse how the server separates and forwards client requests, potentially allowing one client's request data to be mixed with another's and leading to high-impact request handling errors; this is tracked as CVE-2026-86350. Affected releases include Tomcat 11.0.22–11.0.25, 10.1.55–10.1.59, and 9.0.118–9.0.121. Exploitation requires only network access to a Tomcat HTTP/2 endpoint—no credentials or user interaction are needed.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of Apache Software Foundation Apache Tomcat are affected?

BRANCHAFFECTEDFIXED
11.x11.0.22 – 11.0.25
10.x10.1.55 – 10.1.59
9.x9.0.118 – 9.0.121

Is CVE-2026-86350 being exploited?

Public exploit code is available.

How to fix CVE-2026-86350

  1. Restrict network access to Tomcat HTTP/2 ports using firewall rules or access controls.
  2. Disable HTTP/2 support in Tomcat or in front-end proxies/load balancers until a vendor fix is released.
  3. Apply vendor guidance and announcements for official mitigations or patched releases when available.
  4. Monitor HTTP/2 request logs and Web server behavior for signs of request mixing and isolate affected servers.

Frequently asked questions

Is CVE-2026-86350 being actively exploited?

Public exploit code for CVE-2026-86350 is available, which increases the likelihood of active exploitation.

Which Apache Tomcat versions are affected by CVE-2026-86350?

The affected versions are 11.0.22–11.0.25, 10.1.55–10.1.59, and 9.0.118–9.0.121.

Is there a patch for CVE-2026-86350?

No fixed versions are listed in the provided facts and patchAvailable is false; follow the vendor for official patches or mitigations.

Does CVE-2026-86350 require authentication?

No, exploiting this Tomcat vulnerability does not require authentication—network access to the HTTP/2 listener is sufficient.

References