CVE-2025-31651
28.04.2025, 20:15
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.Enginsight
Vendor | Product | Version |
---|---|---|
apache | tomcat | 9.0.0 ≤ 𝑥 < 9.0.104 |
apache | tomcat | 10.1.0 ≤ 𝑥 < 10.1.40 |
apache | tomcat | 11.0.0 ≤ 𝑥 < 11.0.6 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
tomcat10 |
| ||||||||||
tomcat11 |
| ||||||||||
tomcat9 |
|
Vulnerability Media Exposure