Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcatUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-el-3.0-apiUpgrade tomcat-jsvcUpgrade tomcat-docs-webappUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-webappsUpgrade tomcat-libUpgrade tomcat-admin-webapps | Aug 2, 2026 | Aug 2, 2026 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 9.0.120Upgrade Apache Tomcat to 11.0.24Upgrade Apache Tomcat to 10.1.57Upgrade Apache Tomcat to the latest available version | Jul 16, 2026 | Jul 14, 2026 |
| Debian | — | Upgrade tomcat9 | Jul 19, 2026 | Jul 19, 2026 |
| Redhat_linux | — | Upgrade tomcat-admin-webappsUpgrade tomcat9-servlet-4.0-apiUpgrade tomcat9-admin-webappsUpgrade tomcat-libUpgrade tomcat9Upgrade tomcat-jsp-2.3-apiUpgrade jws7-tomcat-javadocUpgrade jws7-tomcat-admin-webappsUpgrade jws7-tomcat-servlet-6.0-apiUpgrade jws7-tomcat-docs-webappNo solution existsUpgrade tomcat9-libUpgrade tomcat-webappsUpgrade tomcatUpgrade tomcat9-el-3.0-apiUpgrade tomcat-servlet-4.0-apiUpgrade jws7-tomcat-webappsUpgrade jws7-tomcat-selinuxUpgrade jws7-tomcat-jsp-3.1-apiUpgrade jws7-tomcat-el-5.0-apiUpgrade tomcat-docs-webappUpgrade tomcat-el-3.0-apiUpgrade tomcat9-webappsUpgrade tomcat9-docs-webappUpgrade tomcat9-jsp-2.3-apiUpgrade jws7-tomcatUpgrade jws7-tomcat-lib | Jul 31, 2026 | Jul 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub