CRITICAL🇵🇱 Wersja polska

CVE-2025-31651

CVSS 9.8v3.1pub. 2025-04-28upd. 2025-11-03

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

🤖 AI Analysis
How it works

An error classified as CWE-116 (Improper Neutralization of Escape, Meta, or Control Sequences) affects the rewrite rules processing mechanism in Apache Tomcat. An attacker may send a specially crafted HTTP request which, in certain though unlikely rewrite rule configurations, causes their bypass. If such rules were the only layer of access control or other security policy, it is possible to circumvent them without any privileges or user interaction.

Impact

An attacker may bypass security restrictions enforced by rewrite rules, potentially leading to unauthorized access to protected resources, breach of confidentiality, integrity, and availability of the application.

Mitigation & patch

Apache Tomcat should be updated to patched versions indicated in vendor references (announcement available at lists.apache.org). The vulnerability affects only configurations using rewrite rules — organizations not using the rewrite module are at lower risk. It is recommended to review existing rewrite rules for enforcement of critical security restrictions.

Who is affected

Apache Tomcat in versions: 11.0.0-M1 to 11.0.5, 10.1.0-M1 to 10.1.39, 9.0.0.M1 to 9.0.102. Version 8.5.0–8.5.100 is marked as EOL but also vulnerable. Older EOL versions may also be affected.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Tomcat

    APP
    Apache
    9.0.0 – 9.0.104 (excl.)10.1.0 – 10.1.40 (excl.)11.0.0 – 11.0.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-24813CRITICAL9.8⚠ KEVPL ✓same product

Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych

CVE-2020-1938CRITICAL9.8⚠ KEVPL ✓same product

Apache Tomcat AJP Connector — odczyt plików i RCE (Ghostcat)

CVE-2016-8735CRITICAL9.8⚠ KEVPL ✓same product

Apache Tomcat RCE przez JmxRemoteLifecycleListener (JMX)

CVE-2026-65182CRITICAL9.1same product

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint b...

CVE-2026-65637CRITICAL9.8same product

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This iss...