Apache Tomcat CVE-2026-77762: A Stale HPACK Emitter Leaks Trailers Between HTTP/2 Requests
Technical analysis of CVE-2026-77762 in Apache Tomcat 11.0.26, covering mechanism, affected versions, exposure context and remediation.
Tag archive
Technical analysis of CVE-2026-77762 in Apache Tomcat 11.0.26, covering mechanism, affected versions, exposure context and remediation.
The problem A team I was helping migrated their API gateway's upstream connections from...
Apache patched CVE-2026-23918, a critical double-free vulnerability in HTTP/2 handling that enables denial-of-service and potential remote code execution. CVSS 8.8. Patch to 2.4.67 immediately.

The HTTP bottleneck that was killing our ecommerce performance When checkout abandonment...

CVE-2026-23918 is a serious vulnerability in Apache HTTP Server that affects the HTTP/2 protocol...

What RPC actually means, what Protocol Buffers and HTTP/2 each contribute, the four streaming patterns, a Go hands-on measured down to the individual HTTP/2 frames, and what made large companies move their internal traffic to gRPC.

TL;DR: HTTP/2 replaces the inefficient six-connection limit of HTTP/1.1 with a single, multiplexed...
Upgrade Required: Node.js released security patches on January 13, 2026 for 8 vulnerabilities...

Hi there, Hope that this blog will give everyone some idea of why gRPC is not natively supported by...

HTTP/2, the successor to the venerable HTTP/1.1, has ushered in a new era of web communication. While...
This is the start of a series of posts about two up-and-coming technologies: HTTP/2 and gRPC. Both...
In this post, I'll explain how you can setup your NGINX for HTTP/2. Go to your nginx.conf or default...