CVE-2026-86350 | Apache Tomcat up to 11.0.25/10.1.59/9.0.121 HTTP/2 Request Processing confused deputy

SecurityVulns

A vulnerability, which was classified as critical, was found in Apache Tomcat up to 11.0.25/10.1.59/9.0.121. This vulnerability affects unknown code of the component HTTP2 Request Processing. Executing a manipulation can lead to unintended intermediary.

This vulnerability appears as CVE-2026-86350. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More