← Back to browse · API

CVE-2025-31651

Severity
CRITICAL
CVSS
9.8
EPSS
0.04047
Risk score
40.62
CISA KEV
No
PoC
No
Published
2025-04-28
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-13626, GHSA-FF77-26X5-69CR
Products
Apache Software Foundation:Apache Tomcat 10.1.0-M1 ≤10.1.39, Apache Software Foundation:Apache Tomcat 11.0.0-M1 ≤11.0.5, Apache Software Foundation:Apache Tomcat 8.5.0 ≤8.5.100, Apache Software Foundation:Apache Tomcat 9.0.0.M1 ≤9.0.102
Sources
euvd EUVD-2025-13626

Description

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

References