PT-2026-97284 · Apache · Apache Tomcat

CVE-2026-77756

·

Published

2026-09-15

·

Updated

2026-10-01

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.25 Apache Tomcat versions 10.1.0-M1 through 10.1.59 Apache Tomcat versions 9.0.47 through 9.0.121 Apache Tomcat versions 8.5.67 through 8.5.100
Description An inconsistent interpretation of HTTP requests, known as HTTP Request/Response Smuggling, occurs when the server processes the transfer-encoding header for an HTTP/1.0 request. This issue can allow an attacker to cause a request from another user to fail when the server is positioned behind a reverse proxy.
Recommendations Upgrade versions 11.0.0-M1 through 11.0.25 to 11.0.26. Upgrade versions 10.1.0-M1 through 10.1.59 to 10.1.60. Upgrade versions 9.0.47 through 9.0.121 to 9.0.122.

Fix

DoS

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TOMCAT-2026-77756
CVE-2026-77756
OPENSUSE-SU-2026:11906-1
OPENSUSE-SU-2026:11907-1
OPENSUSE-SU-2026:11908-1
OPENSUSE-SU-2026:21984-1

Affected Products

Apache Tomcat