External risk intelligence

Tomcat HTTP Request Smuggling Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-86350

Apache Tomcat is a widely used web server and servlet container frequently deployed as a public-facing web or API endpoint. As a core component handling HTTP/2 requests directly at the edge or behind a reverse proxy, it is designed for internet-facing operations, making public exposure the standard deployment pattern for this product.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Apache Tomcat could allow attackers to misinterpret HTTP/2 requests, potentially leading to mixed-up request headers. This issue arises from a regression in a previous fix, impacting various versions of Tomcat. While the exact business impact depends on system configuration, it's important to be aware of potential security risks.

  • HTTP request confusion discovered.
  • Widely used web server technology affected.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted HTTP/2 requests to a vulnerable Apache Tomcat server. This could lead to a mix-up in how request headers are interpreted, potentially allowing the attacker to trick the server into processing requests in unintended ways.

  • Requires network access to the server.
  • Triggered by malformed HTTP/2 requests.
  • Can lead to request header mix-up.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to manipulate how HTTP/2 requests are processed, potentially leading to the misinterpretation of request headers. When supported by the advisory's context, this could affect sensitive information or service behavior if the vulnerable system processes these manipulated requests.

  • User or system data could be at risk.
  • An attacker could send specially crafted requests.
  • Service may behave in unexpected ways.

Operational Fix

Recommended remediation, mitigation, and detection steps

This HTTP/2 request smuggling vulnerability in Apache Tomcat requires immediate attention from infrastructure and platform teams responsible for web application delivery. The first step is to inventory all Tomcat instances, identify public-facing or internally accessible deployments, and assess their business criticality to prioritize remediation efforts.

  • Infrastructure and Platform Teams own remediation.
  • Verify all exposed Tomcat deployments.
  • Plan upgrades during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Apache Tomcat?

Apache Tomcat is a widely deployed open-source web server and servlet container. It serves as the foundation for Java-based web applications, acting as the engine that processes incoming web requests and executes server-side logic to deliver content to users or APIs.

What is the vulnerability in CVE-2026-86350?

This CVE involves a weakness categorized as CWE-444, or HTTP Request/Response Smuggling. It occurs when a server inconsistently interprets the boundaries of HTTP requests. In this case, a regression causes Tomcat to potentially mix up request headers, which may trick the server into misrouting data or processing requests in unintended, insecure ways.

How is this request smuggling triggered?

An attacker triggers this by sending specifically malformed or crafted HTTP/2 requests to the server. Importantly, this issue stems from how the server processes the HTTP/2 protocol stream itself; it does not require a user to click a link, nor is it triggered by standard, well-formed web traffic.

Who should be concerned about this Tomcat issue?

Organizations using the affected Tomcat versions should prioritize this, especially those with public-facing deployments. Halo Surface Signal identifies Tomcat as a common internet-facing component that sits at the edge of networks, meaning any instance exposed to the internet is generally at a higher risk of receiving these malicious requests.

When should I update my Tomcat software?

You should plan to upgrade as soon as your maintenance schedule allows. The first practical step is to create an inventory of all your Tomcat instances to determine which ones are running the affected versions (11.0.22-25, 10.1.55-59, or 9.0.118-121). Once identified, update to the patched versions (11.0.26, 10.1.60, or 9.0.122) to resolve the underlying header interpretation regression.

References