Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59083

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

A flaw was found in Apache Tomcat. This vulnerability, located in the rewrite valve, is due to improper handling of URL encoding (hex encoding). A remote attacker could exploit this to bypass security constraints in certain configurations, potentially gaining unauthorized access or performing actions that should be restricted.

Отчет

This Low impact vulnerability in Apache Tomcat's rewrite valve allows a security constraint bypass through improper URL encoding. Exploitation requires specific configurations and has high attack complexity, limiting its overall risk to Red Hat products.

Меры по смягчению последствий

To mitigate this issue, review Apache Tomcat's rewrite valve configurations. If the rewrite valve is not essential for your application, consider disabling it. If it is required, ensure its configuration does not permit improper URL encoding that could lead to security constraint bypasses. A service restart may be required for changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tomcatAffected
Red Hat Enterprise Linux 10tomcat9Affected
Red Hat Enterprise Linux 6tomcat6Out of support scope
Red Hat Enterprise Linux 7tomcatOut of support scope
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineAffected
Red Hat Enterprise Linux 8tomcatAffected
Red Hat Enterprise Linux 9pki-servlet-engineAffected
Red Hat Enterprise Linux 9tomcatAffected
Red Hat JBoss Web Server 5jws5-tomcatAffected
Red Hat Hardened Imagestomcat11-main-11.0.24-0.1.hum1FixedRHSA-2026:3687208.07.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-807
https://bugzilla.redhat.com/show_bug.cgi?id=2499917tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve

EPSS

Процентиль: 30%
0.0037
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
17 дней назад

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

CVSS3: 9.1
nvd
17 дней назад

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

CVSS3: 9.1
debian
17 дней назад

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apac ...

CVSS3: 9.1
github
17 дней назад

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

EPSS

Процентиль: 30%
0.0037
Низкий

3.7 Low

CVSS3