Skip to content

Apache Tomcat: race condition

High8.1CVE-2026-77762 · Published Sep 23, 2026 · updated Sep 30, 2026

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an attacker to inject trailer fields into another HTTP/2 request. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.39 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60, 9.0.122, which fix the issue.

Affected versions

PackageAffectedFixed in
Apache Tomcat
Product
>= 11.0.0-M1, <= 11.0.25No fix yet
>= 10.1.0-M1, <= 10.1.59No fix yet
>= 9.0.39, <= 9.0.121No fix yet
>= 8.5.59, <= 8.5.100No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Improper Check for Certificate Revocation vulnerability in Apache Tomcat
Medium6.5Sep 23
Apache Tomcat: authentication bypass
Critical9.8Sep 23
Apache Sling XSS: cross-site scripting
Medium6.1Sep 23
Apache Sling XSS: cross-site scripting
Medium6.1Sep 23
Apache Sling XSS: cross-site scripting
Medium6.1Sep 23
Apache Sling XSS: cross-site scripting
Medium6.1Sep 23

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.