cbcvebase.
CVE-2025-31651
published 2025-04-28

CVE-2025-31651: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was…

PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.27%
90.1th percentile
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

Affected

10 ranges
VendorProductVersion rangeFixed in
apachetomcat>= 10.1.0 < 10.1.4010.1.40
apachetomcat>= 11.0.0 < 11.0.611.0.6
apachetomcat>= 9.0.0 < 9.0.1049.0.104
apache_software_foundationapache_tomcat10.1.0-M1 – 10.1.39
apache_software_foundationapache_tomcat11.0.0-M1 – 11.0.5
apache_software_foundationapache_tomcat8.5.0 – 8.5.100
apache_software_foundationapache_tomcat9.0.0.M1 – 9.0.102
debiantomcat10< tomcat10 10.1.40-1 (bookworm)tomcat10 10.1.40-1 (bookworm)
debiantomcat11< tomcat10 10.1.40-1 (bookworm)tomcat10 10.1.40-1 (bookworm)
debiantomcat9< tomcat10 10.1.40-1 (bookworm)tomcat10 10.1.40-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is in Apache Tomcat's Rewrite Valve (RewriteValve) component — detection should focus on HTTP requests targeting paths protected by rewrite rules, particularly those containing escape, meta, or control sequences (e.g., semicolon-delimited path parameters) that may bypass rewrite rule matching.
  • This issue is related to (but not identical to) Apache httpd CVE-2024-38474 — analysts familiar with that CVE's bypass patterns (escape/control sequence injection in rewrite rules) should apply similar detection logic to Tomcat's RewriteValve.
  • ·Only a narrow subset of rewrite rule configurations are vulnerable — specifically those that use rewrite rules as security enforcement mechanisms on raw/unnormalized requestURIs. Default and common configurations are not affected.
  • ·Affected Apache Tomcat versions: 11.0.0-M1 through 11.0.5, 10.1.0-M1 through 10.1.39, 9.0.0.M1 through 9.0.102, and EOL 8.5.0 through 8.5.100. Deployments on these versions with RewriteValve security-enforcing rules should be prioritized for patching.
  • ·Debian fixed the issue in tomcat version 10.1.40-1 across bookworm, forky, sid, and trixie.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.