Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59083

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

A flaw was found in Apache Tomcat. This vulnerability, located in the rewrite valve, is due to improper handling of URL encoding (hex encoding). A remote attacker could exploit this to bypass security constraints in certain configurations, potentially gaining unauthorized access or performing actions that should be restricted.

Отчет

This Low impact vulnerability in Apache Tomcat's rewrite valve allows a security constraint bypass through improper URL encoding. Exploitation requires specific configurations and has high attack complexity, limiting its overall risk to Red Hat products.

Меры по смягчению последствий

To mitigate this issue, review Apache Tomcat's rewrite valve configurations. If the rewrite valve is not essential for your application, consider disabling it. If it is required, ensure its configuration does not permit improper URL encoding that could lead to security constraint bypasses. A service restart may be required for changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tomcatAffected
Red Hat Enterprise Linux 10tomcat9Affected
Red Hat Enterprise Linux 6tomcat6Out of support scope
Red Hat Enterprise Linux 7tomcatOut of support scope
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineAffected
Red Hat Enterprise Linux 8tomcatAffected
Red Hat Enterprise Linux 9pki-servlet-engineAffected
Red Hat Enterprise Linux 9tomcatAffected
Red Hat JBoss Web Server 5jws5-tomcatFix deferred
Red Hat JBoss Web Server 6jws6-tomcatAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-807
https://bugzilla.redhat.com/show_bug.cgi?id=2499917tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve

EPSS

Процентиль: 30%
0.0037
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

CVSS3: 9.1
nvd
2 месяца назад

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

CVSS3: 9.1
debian
2 месяца назад

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apac ...

CVSS3: 9.1
redos
27 дней назад

Уязвимость tomcat11

CVSS3: 9.1
redos
27 дней назад

Уязвимость tomcat10

EPSS

Процентиль: 30%
0.0037
Низкий

3.7 Low

CVSS3