PT-2025-43997 · Apache · Apache Tomcat
Elysee Franchuk
·
Published
2025-09-08
·
Updated
2025-10-30
·
CVE-2025-55754
CVSS v3.1
9.6
  9.6
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H | 
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 8.5.60 through 8.5.100
Apache Tomcat versions 9.0.40 through 9.0.108
Apache Tomcat versions 10.1.0-M1 through 10.1.44
Apache Tomcat versions 11.0.0-M1 through 11.0.10
Description
Tomcat did not properly handle ANSI escape sequences within log messages. When running on a Windows console that supports these sequences, an attacker could potentially inject specially crafted ANSI escape sequences via a URL. This could allow manipulation of the console and clipboard, potentially tricking an administrator into executing attacker-controlled commands. While a specific attack vector was not identified, the possibility of exploitation on other operating systems was noted. The issue involves improper neutralization of escape, meta, or control sequences.
Recommendations
Upgrade to Apache Tomcat version 11.0.11 or later.
Upgrade to Apache Tomcat version 10.1.45 or later.
Upgrade to Apache Tomcat version 9.0.109 or later.
Fix
 Found an issue in the description?  Have something to add?  Feel free to write us 👾 
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
CVE-2025-55754
Affected Products
Apache Tomcat
References · 22
- https://lists.apache.org/thread/j7w54hqbkfcn0xb9xy0wnx8w5nymcbqd · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-55754 · Security Note
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55754 · Note
- https://twitter.com/CriminalIP_US/status/1983351321303580947 · Twitter Post
- https://tomcat.apache.org/security-9 · Note
- https://tomcat.apache.org/security-11 · Note
- https://twitter.com/FindSecCyber/status/1983070291489419620 · Twitter Post
- https://twitter.com/zoomeye_team/status/1983010260974743959 · Twitter Post
- https://twitter.com/oss_security/status/1982992468703621227 · Twitter Post
- https://reddit.com/r/SecOpsDaily/comments/1oj1h3x/cve202555752_and_cve202555754_apache_tomcat · Reddit Post
- https://twitter.com/DCWebGuy/status/1983535210651160637 · Twitter Post
- https://twitter.com/CVEnew/status/1982867549004963937 · Twitter Post
- https://twitter.com/cyberthint/status/1983210515339039114 · Twitter Post
- https://tomcat.apache.org/security-10 · Note
- https://twitter.com/catnap707/status/1982991475286913382 · Twitter Post