PT-2025-18103 · Apache+11 · Apache Tomcat+11

Mark Thomas

·

Published

2025-04-08

·

Updated

2026-05-18

·

CVE-2025-31651

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.5 Apache Tomcat versions 10.1.0-M1 through 10.1.39 Apache Tomcat versions 9.0.0.M1 through 9.0.102
Description The issue is related to the improper neutralization of escape, meta, or control sequences in Apache Tomcat, which could allow a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed.
Recommendations Upgrade to version [FIXED VERSION] to fix the issue for Apache Tomcat versions 11.0.0-M1 through 11.0.5 Upgrade to version [FIXED VERSION] to fix the issue for Apache Tomcat versions 10.1.0-M1 through 10.1.39 Upgrade to version [FIXED VERSION] to fix the issue for Apache Tomcat versions 9.0.0.M1 through 9.0.102

Fix

DoS

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:23048
ALSA-2025:23049
ALSA-2025:23050
ALSA-2025:23052
ALT-PU-2025-13307
ALT-PU-2025-14452
ALT-PU-2025-8715
ALT-PU-2025-9146
BDU:2025-05707
BIT-TOMCAT-2025-31651
CLEANSTART-2026-MR27796
CVE-2025-31651
DLA-4244-1
GHSA-FF77-26X5-69CR
MGASA-2025-0145
OESA-2025-1484
OPENSUSE-SU-2025:15048-1
OPENSUSE-SU-2025:15049-1
OPENSUSE-SU-2025_1521-1
OPENSUSE-SU-2025_1537-1
RHSA-2025:19809
RHSA-2025:22925
RHSA-2025:23044
RHSA-2025:23045
RHSA-2025:23046
RHSA-2025:23047
RHSA-2025:23048
RHSA-2025:23049
RHSA-2025:23050
RHSA-2025:23051
RHSA-2025:23052
RHSA-2025:23053
RHSA-2026:0292
RHSA-2026:0293
RHSA-2026:2724
RHSA-2026:2725
RHSA-2026:2726
SUSE-SU-2025:01521-1
SUSE-SU-2025:01537-1
SUSE-SU-2025:01882-1
SUSE-SU-2025:1521-1
SUSE-SU-2025:1537-1
SUSE-SU-2025_01882-1
SUSE-SU-2026:1058-1
USN-7705-1

Affected Products

Alt Linux
Almalinux
Apache Tomcat
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu