DEV Community

jeffrey
jeffrey

Posted on

Patch Matrix for CVE-2026-86350: Which Apache Tomcat Builds Need 11.0.26, 10.1.60 or 9.0.122

Patch Matrix for CVE-2026-86350: Which Apache Tomcat Builds Need 11.0.26, 10.1.60 or 9.0.122

Operator summary

CVE-2026-86350 is an Important-severity Apache Tomcat defect involving a request header mix-up in HTTP/2 handling. It is a regression from the fix for CVE-2026-41293. Remediation is a version move, and the correct target depends on the branch a server runs.

Patch matrix

Branch Vulnerable range Fixed release Vendor commit
Tomcat 11.0.x 11.0.22 to 11.0.25 11.0.26 192bc749
Tomcat 10.1.x 10.1.55 to 10.1.59 10.1.60 259e938d
Tomcat 9.0.x 9.0.118 to 9.0.121 9.0.122 5adadc4e

Tomcat 8.5 does not appear against this CVE on the vendor security pages. Older 11.0.x, 10.1.x and 9.0.x builds outside the listed ranges are not covered by the regression.

Why the ranges start where they do

The vulnerable code entered the tree with the CVE-2026-41293 fix, so the exposure window is bounded by that commit and the corrective commit in each branch. Because the ranges are contiguous and short, an inventory that records exact Tomcat build numbers can classify hosts immediately rather than by guesswork.

Severity and scoring

Apache labels the entry Important. The project does not publish a CVSS vector for it in the 11 security page. A third-party release roundup assigns 9.1 under CWE-444 to CVE-2026-86350; that number comes from the aggregator and should be treated as context, not as a vendor score.

Verification checklist

  1. Read the exact server version from the Tomcat startup log or from the manager application.
  2. Confirm whether any connector has HTTP/2 enabled, since the defect lives in HTTP/2 request interpretation.
  3. Check whether an upstream proxy or load balancer rewrites or pools HTTP/2 requests in front of Tomcat.
  4. Record the fix commit hash for the branch in use so change tickets can cite it.

Exposure snapshot

ZoomEye returns 580,597 results for app="Apache Tomcat" (about 580.6k assets), while vul.cve="CVE-2026-86350" returns 0. The gap is normal for a freshly published CVE and means the product count reflects the size of the exposed Tomcat base, not confirmed vulnerable instances.

Mitigation while change control runs

Disable HTTP/2 on the affected connector if the upgrade cannot be scheduled quickly. Log review for HTTP/2 requests with mismatched header expectations gives an early signal. Neither control replaces the patch, and both should be revisited once 11.0.26, 10.1.60 or 9.0.122 is deployed.

References

Top comments (0)