CVE-2025-55754Improper Neutralization of Escape, Meta, or Control Sequences in Apache Tomcat

Severity
9.6CRITICALNVD
EPSS
0.1%
top 67.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27

Description

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While n

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 2.8 | Impact: 6.0

Affected Packages2 packages

CVEListV5apache_software_foundation/apache_tomcat11.0.0-M111.0.10+3
NVDapache/tomcat9.0.409.0.109+4

🔴Vulnerability Details

4
GHSA
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences2025-10-27
CVEList
Apache Tomcat: console manipulation via escape sequences in log messages2025-10-27
OSV
CVE-2025-55754: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat2025-10-27
OSV
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences2025-10-27

📋Vendor Advisories

2
Red Hat
org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation2025-10-27
Debian
CVE-2025-55754: tomcat10 - Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in A...2025

💬Community

2
Bugzilla
CVE-2025-55754 tomcat: Apache Tomcat: console manipulation [fedora-42]2025-10-27
Bugzilla
CVE-2025-55754 org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation2025-10-27
CVE-2025-55754 — Apache Tomcat vulnerability | cvebase