Product
A critical HTTP/2 request smuggling vulnerability, CVE-2026-86350, allows unauthenticated attackers to induce dynamic table desynchronization in Apache Tomcat via crafted header blocks.