CVE-2025-55754
published 2025-10-27CVE-2025-55754: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If…
PriorityP265critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
10.14%
95.2th percentile
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.
Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 10.0.0 < 10.0.27 | 10.0.27 |
| apache | tomcat | >= 10.1.0 < 10.1.45 | 10.1.45 |
| apache | tomcat | >= 11.0.0 < 11.0.11 | 11.0.11 |
| apache | tomcat | 8.5.60 – 8.5.100 | — |
| apache | tomcat | >= 9.0.40 < 9.0.109 | 9.0.109 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.44 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.10 | — |
| apache_software_foundation | apache_tomcat | 8.5.60 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.40 – 9.0.108 | — |
| debian | tomcat10 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat11 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector is a specially crafted URL containing ANSI escape sequences injected into Tomcat log messages; monitor HTTP access logs for requests containing ANSI escape sequence patterns (ESC [ sequences, i.e., \x1b[ or \033[) in URL paths or query strings ↗
- →Vulnerable component is Apache Tomcat's logging subsystem (tomcat-juli); focus detection on Tomcat versions 11.0.0-M1 through 11.0.10, 10.1.0-M1 through 10.1.44, 9.0.40 through 9.0.108, and 8.5.60 through 8.5.100 ↗
- →Exploitation is most impactful when Tomcat is running in a Windows console that supports ANSI escape sequences; prioritize detection on Windows-hosted Tomcat instances where console output is visible to administrators ↗
- ·No active exploitation in the wild has been confirmed by SAP or other vendors at the time of disclosure; the CVE description itself notes 'no attack vector was found' for the Windows console attack path ↗
- ·Red Hat has deferred fixes for many affected packages (tomcat-juli in JBoss EAP, Fuse, SSO, Data Grid, etc.); patched versions are 11.0.11+, 10.1.45+, and 9.0.109+ ↗
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
osv9.6CRITICAL
vendor_debian9.6CRITICAL
vendor_redhat9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
ghsa·2025-10-27
CVE-2025-55754 [LOW] CWE-150 Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108.
The following versions were EOL at the time the CVE was created but are
OSV
CVE-2025-55754: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat
osv·2025-10-27·CVSS 9.6
CVE-2025-55754 [CRITICAL] CVE-2025-55754: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108. The following versions were EOL at the time the CVE was created but are
OSV
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
osv·2025-10-27
CVE-2025-55754 [LOW] Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108.
The following versions were EOL at the time the CVE was created but are
Red Hat
org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation
vendor_redhat·2025-10-27·CVSS 9.6
CVE-2025-55754 [CRITICAL] CWE-150 org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation
org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.
Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.1
Debian
CVE-2025-55754: tomcat10 - Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in A...
vendor_debian·2025·CVSS 9.6
CVE-2025-55754 [CRITICAL] CVE-2025-55754: tomcat10 - Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in A...
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108. The following versions were EOL at the time the CVE was created but are
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-55754 tomcat: Apache Tomcat: console manipulation [fedora-42]
bugzilla·2025-10-27·CVSS 9.6
CVE-2025-55754 [CRITICAL] CVE-2025-55754 tomcat: Apache Tomcat: console manipulation [fedora-42]
CVE-2025-55754 tomcat: Apache Tomcat: console manipulation [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Bugzilla
CVE-2025-55754 org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation
bugzilla·2025-10-27·CVSS 9.6
CVE-2025-55754 [CRITICAL] CVE-2025-55754 org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation
CVE-2025-55754 org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.
Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.
Bugzilla
CVE-2025-55754 log4j: Apache Tomcat: console manipulation [fedora-42]
bugzilla·2025-10-27·CVSS 9.6
CVE-2025-55754 [CRITICAL] CVE-2025-55754 log4j: Apache Tomcat: console manipulation [fedora-42]
CVE-2025-55754 log4j: Apache Tomcat: console manipulation [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from relea
Bugzilla
CVE-2025-55754 jss: Apache Tomcat: console manipulation [fedora-42]
bugzilla·2025-10-27·CVSS 9.6
CVE-2025-55754 [CRITICAL] CVE-2025-55754 jss: Apache Tomcat: console manipulation [fedora-42]
CVE-2025-55754 jss: Apache Tomcat: console manipulation [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from release
Checkpoint
15th December – Threat Intelligence Report
blogs_checkpoint·2025-12-15
CVE-2025-14174 15th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 15th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 15th December, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The Indian government confirmed cyber incidents involving GPS spoofing at seven major airports, including Delhi, Mumbai, Kolkata, and Bengaluru. The attack affected aircrafts using GPS-based landing procedures. Despite signal disruption to navigation data, authorities stated no flights were cancelled or diverted, with c
Bleepingcomputer
SAP fixes three critical vulnerabilities across multiple products
blogs_bleepingcomputer·2025-12-09·CVSS 9.9
CVE-2025-42880 [CRITICAL] SAP fixes three critical vulnerabilities across multiple products
## SAP fixes three critical vulnerabilities across multiple products
## Bill Toulas
SAP has released its December security updates addressing 14 vulnerabilities across a range of products, including three critical-severity flaws.
The most severe (CVSS score: 9.9) of all the issues is CVE-2025-42880 , a code injection problem impacting SAP Solution Manager ST 720.
"Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module," reads the flaw's description.
"This could provide the attacker with full control of the system, hence leading to high impact on confidentiality, integrity, and availability of the system."
SAP Solution Manager is the vendor's central lifecycle management and monitori
2025-10-27
Published