Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25854

Опубликовано: 09 апр. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100. Other, unsupported versions may also be affected Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

A flaw was found in Apache Tomcat. This open redirect vulnerability allows an attacker to redirect a user to an untrusted site. This occurs through the LoadBalancerDrainingValve, which can be exploited to manipulate URL redirection. The primary impact is that users may be unknowingly directed to malicious websites, potentially leading to phishing attacks or other security compromises.

Отчет

This Low impact vulnerability in Apache Tomcat allows for an open redirect through the LoadBalancerDrainingValve. An attacker could exploit this to redirect users to malicious websites, potentially leading to phishing. This affects Red Hat Enterprise Linux and Red Hat JBoss Web Server when Apache Tomcat is configured with the LoadBalancerDrainingValve.

Меры по смягчению последствий

To mitigate this vulnerability, disable or remove the LoadBalancerDrainingValve configuration from the server.xml file in your Apache Tomcat installation. This valve is typically configured within a or element. After modifying server.xml, restart the Apache Tomcat service for the changes to take effect. This action may impact load balancing functionality if the valve is actively used for draining connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tomcatFix deferred
Red Hat Enterprise Linux 6tomcat6Out of support scope
Red Hat Enterprise Linux 7tomcatFix deferred
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineFix deferred
Red Hat Enterprise Linux 8tomcatFix deferred
Red Hat Enterprise Linux 9pki-servlet-engineFix deferred
Red Hat Enterprise Linux 9tomcatFix deferred
Red Hat JBoss Web Server 5tomcatFix deferred
Red Hat Enterprise Linux 10tomcat9FixedRHSA-2026:3679008.07.2026
Red Hat JBoss Web Server 6.2.3tomcatFixedRHSA-2026:2040626.05.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2457039Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve

EPSS

Процентиль: 41%
0.00526
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
4 месяца назад

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100. Other, unsupported versions may also be affected Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

CVSS3: 6.1
nvd
4 месяца назад

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100. Other, unsupported versions may also be affected Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

CVSS3: 6.1
debian
4 месяца назад

Occasional URL redirection to untrusted Site ('Open Redirect') vulnera ...

CVSS3: 6.1
github
4 месяца назад

Apache Tomcat has an Open Redirect vulnerability

CVSS3: 6.1
fstec
4 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с переадресацией url на ненадежный сайт, позволяющая нарушителю перенаправить пользователя на произвольный url-адрес

EPSS

Процентиль: 41%
0.00526
Низкий

4.3 Medium

CVSS3