All verified exploits

CVE-2026-86350 HTTP/2 Request Header Mix-Up (Request Smuggling)

CVE-2026-86350 is a critical-severity vulnerability. AttackerView checks Apache Tomcat sites for it with a live exploit check.

Deterministic critical Apache Tomcat Added cve-verified-cve-2026-86350

Is my site vulnerable to CVE-2026-86350?

Detects Apache Tomcat servers whose HTTP/2 connector mixes headers between requests on the same connection. The compression scheme HTTP/2 uses for headers keeps a shared table that both sides have to agree on for the whole connection. On these versions Tomcat checks each header for illegal characters from inside that shared decoder, and when it finds one it stops reading the rest of the request's headers but keeps the connection open. Everything after the rejected header is therefore never recorded, so the two sides no longer agree on the table, and every later request on that connection resolves indexed headers to the wrong values. We show that with two connections. On the first, a marker header is stored and then re-used by index on a second request, which answers. On the second connection that same second request goes unanswered, because one extra header with a trailing space was placed ahead of the marker. Upgrade Tomcat to 11.0.26, 10.1.60 or 9.0.122. Until you upgrade, turn HTTP/2 off on every connector.

Is your app exploitable through CVE-2026-86350?

Scan your domain free