Back

HIGH

Apache Tomcat: HTTP/2 DoS via malformed request

Published Sep 23, 2026

Description

Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail.

This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121.

Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 23, 2026
Updated Sep 23, 2026
Reserved Aug 24, 2026
CISA Vulnrichment
Updated Sep 23, 2026
NVD
Status Awaiting Analysis
Modified Sep 23, 2026
Red Hat
Severity n/a
Public date n/a