CVE-2025-31651
published 2025-04-28CVE-2025-31651: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible
for a specially crafted request to bypass some rewrite rules. If those
rewrite rules effectively enforced security constraints, those
constraints could be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 10.1.0 < 10.1.40 | 10.1.40 |
| apache | tomcat | >= 11.0.0 < 11.0.6 | 11.0.6 |
| apache | tomcat | >= 9.0.0 < 9.0.104 | 9.0.104 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.39 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.5 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.102 | — |
| debian | tomcat10 | < tomcat10 10.1.40-1 (bookworm) | tomcat10 10.1.40-1 (bookworm) |
| debian | tomcat11 | < tomcat10 10.1.40-1 (bookworm) | tomcat10 10.1.40-1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.40-1 (bookworm) | tomcat10 10.1.40-1 (bookworm) |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL