{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/apache-tomcat--9.0.121-10.1.55-10.1.59-11.0.22-11.0.25/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-86350"},{"cvss":9.8,"id":"CVE-2026-41293"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Apache Tomcat (\u003c= 9.0.121, 10.1.55-10.1.59, 11.0.22-11.0.25)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","webserver","request-smuggling"],"_cs_type":"advisory","_cs_vendors":["Apache Software Foundation"],"content_html":"\u003cp\u003eCVE-2026-86350 is a critical HTTP/2 request smuggling vulnerability affecting Apache Tomcat versions through 9.0.121, 10.1.55-10.1.59, and 11.0.22-11.0.25. The flaw originates from a regression in the HPACK header validation logic introduced during the refactor for CVE-2026-41293. When an attacker sends a specially crafted HTTP/2 request containing an invalid HPACK field, the decoder throws an exception and halts processing, preventing subsequent fields in that request from being added to the HPACK dynamic table.\u003c/p\u003e\n\u003cp\u003eBecause the dynamic table state becomes desynchronized, subsequent HTTP/2 requests multiplexed over the same TCP connection will index headers against an incorrect or stale table state. This allows for header mixing or request smuggling, where an attacker can influence the interpretation of later requests. This vulnerability is rated with a CVSS score of 9.1 and represents a significant risk for environments relying on HTTP/2 multiplexing. The vulnerability does not provide direct remote code execution, but facilitates security bypasses by poisoning the request context.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes a standard HTTP/2 connection with the target Apache Tomcat server via a preface.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an HTTP/2 stream (Stream 1) and submits a HEADERS frame containing a malformed or invalid field value.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eHpackDecoder\u003c/code\u003e processes the stream and encounters the invalid field, triggering an \u003ccode\u003eIllegalArgumentException\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe decoder terminates the processing of Stream 1, intentionally failing to update the HPACK dynamic table with subsequent valid headers.\u003c/li\u003e\n\u003cli\u003eThe server keeps the TCP connection open, maintaining the desynchronized dynamic table state.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a second HTTP/2 stream (Stream 2) on the same connection, using indices that rely on the expected state of the dynamic table.\u003c/li\u003e\n\u003cli\u003eThe Tomcat server processes Stream 2 using the corrupted table state, causing the server to misinterpret the attacker's headers.\u003c/li\u003e\n\u003cli\u003eThe final objective is achieved when the smuggled request is processed with the attacker's injected header context, potentially bypassing access controls or application logic.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to smuggle requests, potentially bypassing security controls, gaining unauthorized access to sensitive application paths, or manipulating request routing. While not a direct RCE, the ability to desynchronize request headers allows for complex application-layer attacks. The vulnerability affects a wide range of Tomcat deployments globally where HTTP/2 is enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Apache Tomcat to 9.0.122, 10.1.60, 11.0.26, or newer immediately to patch the HPACK validation regression.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, disable HTTP/2 support in the Tomcat configuration until patching is complete.\u003c/li\u003e\n\u003cli\u003eEnsure the 'examples' web application is removed from production environments to reduce the surface area for testing and exploitation.\u003c/li\u003e\n\u003cli\u003eHunt for anomalous HTTP/2 traffic patterns or logs indicating frequent \u003ccode\u003eIllegalArgumentException\u003c/code\u003e events originating from the \u003ccode\u003eorg.apache.coyote.http2\u003c/code\u003e package in server logs.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-26T01:35:48Z","date_published":"2026-09-26T01:35:48Z","id":"https://feed.craftedsignal.io/briefs/2026-09-tomcat-http2-smuggling/","summary":"A critical HTTP/2 request smuggling vulnerability, CVE-2026-86350, allows unauthenticated attackers to induce dynamic table desynchronization in Apache Tomcat via crafted header blocks.","title":"Apache Tomcat HTTP/2 Request Smuggling Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-tomcat-http2-smuggling/"}],"language":"en","title":"CraftedSignal Threat Feed - Apache Tomcat (\u003c= 9.0.121, 10.1.55-10.1.59, 11.0.22-11.0.25)","version":"https://jsonfeed.org/version/1.1"}