9.1

CVE-2026-59083

Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.

Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheTomcat Version <= 8.0.0
ApacheTomcat Version >= 8.5.0 <= 8.5.100
ApacheTomcat Version >= 9.0.0 <= 9.0.119
ApacheTomcat Version >= 10.1.0 <= 10.1.56
ApacheTomcat Version >= 11.0.0 <= 11.0.23
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.295
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-177 Improper Handling of URL Encoding (Hex Encoding)

The product does not properly handle when all or part of an input has been URL encoded.

https://lists.apache.org/thread/3g63zos2gkjo5vgnrk8kxmosv47w6wbq
Vendor Advisory
Mitigation
http://www.openwall.com/lists/oss-security/2026/07/14/7
Third Party Advisory
Mailing List