CVE-2026-41293: Apache Tomcat: HTTP/2 request headers not validated
Improper Input Validation vulnerability in Apache Tomcat.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tomcat10to a version that resolves this vulnerability.Fixed in 10.1.55-1~deb12u1Fixed in 10.1.55-1~deb13u1Fixed in 10.1.55-1 - Upgrade
Upgrade
debian/tomcat11to a version that resolves this vulnerability.Fixed in 11.0.22-1~deb13u1Fixed in 11.0.22-2 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.118-0+deb11u1Fixed in 9.0.70-2Fixed in 9.0.95-1Fixed in 9.0.118-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41293?
CVE-2026-41293 is rated as a medium severity vulnerability due to improper input validation in Apache Tomcat's HTTP/2 request headers.
How do I fix CVE-2026-41293?
To fix CVE-2026-41293, update your Apache Tomcat instance to a version that is not affected, specifically to versions 11.0.22 or later, 10.1.55 or later, 9.0.118 or later, or 10.0.28 or later.
Which versions of Apache Tomcat are affected by CVE-2026-41293?
CVE-2026-41293 affects Apache Tomcat versions from 11.0.0-M1 to 11.0.21, 10.1.0-M1 to 10.1.54, 9.0.0.M1 to 9.0.117, and 10.0.0-M1 to 10.0.27.
What are the potential impacts of CVE-2026-41293?
If exploited, CVE-2026-41293 could allow an attacker to manipulate HTTP/2 request headers, potentially leading to unauthorized access or service disruption.
Is there a workaround for CVE-2026-41293 until I can update?
There are no official workarounds for CVE-2026-41293; it is recommended to apply the update as soon as possible.