MAVEN · MAY 2026 · EARLY WARNING

Apache Tomcat HTTP/2 Header Validation Issue: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
apache tomcat (maven)
Patched version
11.0.22 || 10.1.55 || 9.0.118
GHSA-R29C-68GH-XP6X

An early warning has been issued for a critical vulnerability in Apache Tomcat versions 11.0.0-M1 to 11.0.21, 10.1.0-M1 to 10.1.54, and 9.0.0.M1 to 9.0.117. These versions do not validate HTTP/2 request headers, which may lead to unexpected application behavior.

What happened

Apache Tomcat versions 11.0.0-M1 to 11.0.21, 10.1.0-M1 to 10.1.54, and 9.0.0.M1 to 9.0.117 reportedly do not validate HTTP/2 request headers. This oversight may result in unexpected application behavior, as the server does not properly scrutinize incoming HTTP/2 headers. The vulnerability, tracked as GHSA-R29C-68GH-XP6X and CVE-2026-41293, has a high severity rating. It is under investigation whether older, unsupported versions are also affected.

This issue was first flagged on May 12, 2026, and has not yet been exploited in the wild according to current reports. The vulnerability does not appear to be part of a supply-chain attack at this time. Users of the affected versions are advised to take immediate action to assess their exposure and apply the recommended patches.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If apache tomcat is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using Apache Tomcat versions 11.0.0-M1 to 11.0.21, 10.1.0-M1 to 10.1.54, or 9.0.0.M1 to 9.0.117.

What should I do right now?

Immediately upgrade to Apache Tomcat 11.0.22 or later, 10.1.55 or later, or 9.0.118 or later.

Is this vulnerability being exploited in the wild?

There are no reports of this vulnerability being exploited in the wild at this time.

Are there any known workarounds for this issue?

No official workarounds have been published. The recommended action is to upgrade to a patched version.

Sources

Join the 0Day waitlist →

← Back to all threats