CVE-2026-25854
published 2026-04-09CVE-2026-25854: Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache…
PriorityP432medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.53%
41.0th percentile
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100.
Other, unsupported versions may also be affected
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.0 < 10.1.53 | 10.1.53 |
| apache | tomcat | >= 11.0.0 < 11.0.20 | 11.0.20 |
| apache | tomcat | >= 9.0.1 < 9.0.116 | 9.0.116 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.52 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.18 | — |
| apache_software_foundation | apache_tomcat | 8.5.30 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M23 – 9.0.115 | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve
vendor_redhat·2026-04-09·CVSS 6.1
CVE-2026-25854 [MEDIUM] CWE-601 Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve
Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100.
Other, unsupported versions may also be affected
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
A flaw was found in Apache Tomcat. This open redirect vulnerability allows an attacker to redirect a user to an untrusted site. This occurs through the LoadBalancerDrainingValve, which can be exploited to manipulate URL redirection. The primary impact is that users may be unknow
GHSA
Apache Tomcat has an Open Redirect vulnerability
ghsa·2026-04-09
CVE-2026-25854 [MEDIUM] CWE-601 Apache Tomcat has an Open Redirect vulnerability
Apache Tomcat has an Open Redirect vulnerability
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100.
Other, unsupported versions may also be affected
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
GHSA
GHSA-9m3c-qcxr-9x87: Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve
ghsa_unreviewed·2026-04-09
CVE-2026-25854 CWE-601 GHSA-9m3c-qcxr-9x87: Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100.
Other, unsupported versions may also be affected
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
VulDB
Apache Tomcat up to 7.0.108/8.5.100/9.0.115/10.1.52/11.0.18 redirect
vuldb·2026-04-09·CVSS 6.1
CVE-2026-25854 [MEDIUM] Apache Tomcat up to 7.0.108/8.5.100/9.0.115/10.1.52/11.0.18 redirect
A vulnerability categorized as problematic has been discovered in Apache Tomcat up to 7.0.108/8.5.100/9.0.115/10.1.52/11.0.18. Impacted is an unknown function. The manipulation results in open redirect.
This vulnerability was named CVE-2026-25854. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-25854 tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve [fedora-all]
bugzilla·2026-04-10·CVSS 6.1
CVE-2026-25854 [MEDIUM] CVE-2026-25854 tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve [fedora-all]
CVE-2026-25854 tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-25854 Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve
bugzilla·2026-04-09·CVSS 6.1
CVE-2026-25854 [MEDIUM] CVE-2026-25854 Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve
CVE-2026-25854 Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100.
Other, unsupported versions may also be affected
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
2026-04-09
Published