CVE-2026-77762 | Apache Tomcat up to 11.0.25/10.1.59/9.0.121 HTTP/2 race condition

SecurityVulns

A vulnerability categorized as critical has been discovered in Apache Tomcat up to 11.0.25/10.1.59/9.0.121. The affected element is an unknown function of the component HTTP2. Such manipulation leads to race condition.

This vulnerability is referenced as CVE-2026-77762. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More