
🔴 Apache Tomcat'te CVSS 9.1 Critical HTTP/2 Request Smuggling açığı için @abraxas_null tarafından PoC yayınlandı. CVE-2026-86350, CVE-2026-41293 için yapılan düzeltmedeki regression nedeniyle HTTP/2 HPACK decoder state'inin bozulmasına ve aynı bağlantıdaki sonraki request'lerin header'larının yanlış yorumlanmasına yol açabiliyor. Unauthenticated / Remote — CWE-444 — CVSS 9.1 Etkilenen sürümler: 9.0.118–9.0.121, 10.1.55–59, 11.0.22–25 Düzeltilenler: 9.0.122 / 10.1.60 / 11.0.26 Yayınlanan PoC RCE değil; HTTP/2 header mix-up / request-smuggling koşulunu doğrulayan bir lab PoC'si. https://github.com/abraxas/CVE-2026-86350
Post summary
The tweet announces the release of a proof-of-concept for a critical Apache Tomcat HTTP/2 request smuggling vulnerability, providing technical details and patched versions while clarifying the PoC is not an RCE exploit.





