CVE-2025-31651
published 2025-04-28CVE-2025-31651: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was…
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.27%
90.0th percentile
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible
for a specially crafted request to bypass some rewrite rules. If those
rewrite rules effectively enforced security constraints, those
constraints could be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 10.1.0 < 10.1.40 | 10.1.40 |
| apache | tomcat | >= 11.0.0 < 11.0.6 | 11.0.6 |
| apache | tomcat | >= 9.0.0 < 9.0.104 | 9.0.104 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.39 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.5 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.102 | — |
| debian | tomcat10 | < tomcat10 10.1.40-1 (bookworm) | tomcat10 10.1.40-1 (bookworm) |
| debian | tomcat11 | < tomcat10 10.1.40-1 (bookworm) | tomcat10 10.1.40-1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.40-1 (bookworm) | tomcat10 10.1.40-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is in Apache Tomcat's Rewrite Valve (RewriteValve) component — detection should focus on HTTP requests targeting paths protected by rewrite rules, particularly those containing escape, meta, or control sequences (e.g., semicolon-delimited path parameters) that may bypass rewrite rule matching. ↗
- →This issue is related to (but not identical to) Apache httpd CVE-2024-38474 — analysts familiar with that CVE's bypass patterns (escape/control sequence injection in rewrite rules) should apply similar detection logic to Tomcat's RewriteValve. ↗
- ·Only a narrow subset of rewrite rule configurations are vulnerable — specifically those that use rewrite rules as security enforcement mechanisms on raw/unnormalized requestURIs. Default and common configurations are not affected. ↗
- ·Affected Apache Tomcat versions: 11.0.0-M1 through 11.0.5, 10.1.0-M1 through 10.1.39, 9.0.0.M1 through 9.0.102, and EOL 8.5.0 through 8.5.100. Deployments on these versions with RewriteValve security-enforcing rules should be prioritized for patching. ↗
- ·Debian fixed the issue in tomcat version 10.1.40-1 across bookworm, forky, sid, and trixie. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Application Interface (Apache Tomcat) — CVE-2025-31651
vendor_oracle·2025-10-15·CVSS 9.8
CVE-2025-31651 [CRITICAL] Oracle Oracle Siebel CRM Risk Matrix: Application Interface (Apache Tomcat) — CVE-2025-31651
Oracle Oracle Siebel CRM Risk Matrix: Application Interface (Apache Tomcat) vulnerability
CVE: CVE-2025-31651
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2025-08-20·CVSS 9.8
CVE-2024-50379 [CRITICAL] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat did not correctly handle case sensitivity.
An attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-46701)
Elysee Franchuk discovered that Tomcat did not correctly limit the number
of attributes for a session. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.04 LTS.
(CVE-2024-54677)
It was discovered that Tomcat did not correctly sanitize certain URLs. An
attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-31651)
It was discovered that Tomcat did not correctly handle certain malformed
HTTP headers,
which could lead to a memory leak. An attacker could
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Runtime Server (Apache Tomcat) — CVE-2025-31651
vendor_oracle·2025-07-15·CVSS 9.8
CVE-2025-31651 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Runtime Server (Apache Tomcat) — CVE-2025-31651
Oracle Oracle Fusion Middleware Risk Matrix: Runtime Server (Apache Tomcat) vulnerability
CVE: CVE-2025-31651
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Red Hat
tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve
vendor_redhat·2025-04-28·CVSS 9.8
CVE-2025-31651 [CRITICAL] CWE-150 tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve
tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible
for a specially crafted request to bypass some rewrite rules. If those
rewrite rules effectively enforced security constraints, those
constraints could be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
A flaw was found in Apache Tomcat's
Debian
CVE-2025-31651: tomcat10 - Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in A...
vendor_debian·2025·CVSS 9.8
CVE-2025-31651 [CRITICAL] CVE-2025-31651: tomcat10 - Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in A...
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Scope: local
bookworm: resolved (fixed in 10.1.40-1)
forky: resolved (fixed in 10.1.40-1)
sid:
OSV
tomcat10 vulnerabilities
osv·2025-08-20·CVSS 9.8
CVE-2025-46701 [CRITICAL] tomcat10 vulnerabilities
tomcat10 vulnerabilities
It was discovered that Tomcat did not correctly handle case sensitivity.
An attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-46701)
Elysee Franchuk discovered that Tomcat did not correctly limit the number
of attributes for a session. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.04 LTS.
(CVE-2024-54677)
It was discovered that Tomcat did not correctly sanitize certain URLs. An
attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-31651)
It was discovered that Tomcat did not correctly handle certain malformed
HTTP headers,
which could lead to a memory leak. An attacker could possibly use this
issue to cause a denial of service. This i
OSV
CVE-2025-31651: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat
osv·2025-04-28·CVSS 9.8
CVE-2025-31651 [CRITICAL] CVE-2025-31651: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
OSV
Apache Tomcat Rewrite rule bypass
osv·2025-04-28
CVE-2025-31651 [LOW] Apache Tomcat Rewrite rule bypass
Apache Tomcat Rewrite rule bypass
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6, which fix the issue.
GHSA
Apache Tomcat Rewrite rule bypass
ghsa·2025-04-28
CVE-2025-31651 [LOW] CWE-116 Apache Tomcat Rewrite rule bypass
Apache Tomcat Rewrite rule bypass
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6, which fix the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-31651 tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve
bugzilla·2025-04-28·CVSS 9.8
CVE-2025-31651 [CRITICAL] CVE-2025-31651 tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve
CVE-2025-31651 tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible
for a specially crafted request to bypass some rewrite rules. If those
rewrite rules effectively enforced security constraints, those
constraints could be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Discussion:
see apache httpd CVE-2024-38474, this issue is not identical
---
This issue has been addressed in the following products:
Red Hat JBoss Web Server 6.1.3
Via RHSA-2025:
Qualys
Oracle Critical Patch Update, July 2025 Security Update Review
blogs_qualys·2025-07-16
Oracle Critical Patch Update, July 2025 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 309 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 84, constituting about 27% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 40 and 36 security patches.
228 of the 309 security patches provided by the July Critical Patch Update (about 74%) are for non-Oracle CVEs, su
Qualys
Oracle Critical Patch Update, July 2025 Security Update Review | Qualys
blogs_qualys·2025-07-16
Oracle Critical Patch Update, July 2025 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 309 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 84, constituting about 27% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 40 and 36 security patches.
228 of the 309 security patches provided by the July Critical Patch Update (about 74%) are for non-Oracle CVE
2025-04-28
Published