Why CVE-2026-77762 Shows a Vendor Low Rating and a Third-Party 8.1 Score
Two numbers, one identifier
Anyone comparing sources for CVE-2026-77762 will hit a contradiction. The Apache Tomcat advisory page rates the entry Low. The collection roundup that surfaced the release lists the same identifier with a CVSS score of 8.1 and a CWE-362, Race Condition, tag. Both numbers describe the same bug, and the gap between them is the interesting part.
What Apache is measuring
The Tomcat security team's rating reflects what an attacker gets on a default deployment. For CVE-2026-77762, the advisory text is a single sentence: a race condition allowed an attacker to inject trailer fields into another HTTP/2 request. Trailers are an optional part of an HTTP message, delivered after the body. A servlet or framework that reads headers and payload and ignores trailers will not consume the injected values at all. For that majority case the exploit delivers nothing observable, which is the reasoning behind a Low rating.
What the scoring framework is measuring
A generic CVSS vector, by contrast, rewards attack complexity that is still reachable across a network, and it struggles to encode "only matters if the application reads this part of the message". Ambiguity about confidentiality and integrity impact on trailers is enough to push a base score upward. The count of affected versions also plays a part: 11.0.0-M1 through 11.0.25 is a very wide range, so the identifier inherits urgency from the size of the installed base rather than from the severity of the primitive.
How to reconcile them in practice
Neither rating is wrong; they answer different questions. Apache answers "what happens if I run Tomcat as shipped". The third-party score answers "how bad is this primitive in the abstract". A working prioritisation rule follows from that split.
- If no application on the host reads HTTP/2 trailers, CVE-2026-77762 is a low-priority item for you and belongs in the normal upgrade train.
- If an application does parse trailers, treat the identifier as high priority regardless of the vendor label, because trait of the bug is attacker-controlled input reaching your code.
- Either way, the fix is the same release. Tomcat 11.0.26 contains commit fd309997.
Impact
Cross-request injection of trailer fields, gated by a timing race and by whether the application consumes trailers.
Affected products
Apache Tomcat 11.0.0-M1 through 11.0.25.
Exposure
ZoomEye reports 580,597 instances for app="Apache Tomcat". A query for vul.cve="CVE-2026-77762" returns zero hosts, which is consistent with a flaw that has no external signature and cannot be found by CVE tag.
Search link: https://www.zoomeye.ai/searchResult?q=YXBwPSJBcGFjaGUgVG9tY2F0Ig%3D%3D
Remediation
Upgrade to Tomcat 11.0.26 or later and add a targeted code review for trailer consumption. The advisory documents only the code fix, so any trailer-handling change is your own compensating control rather than an official workaround.
References
- Apache Tomcat 11.x vulnerabilities: https://tomcat.apache.org/security-11.html
- Tomcat 11 downloads: https://tomcat.apache.org/download-11.cgi
- Collection source: https://securityonline.info/apache-tomcat-vulnerabilities-11-0-26/
Top comments (0)