Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
2.7
CVE-2025-31651: Apache Tomcat: Specially crafted requests can bypass security rules
GHSA-ff77-26x5-69cr
CVE-2025-31651
BIT-tomcat-2025-31651
CVE-2025-31651
Summary
Apache Tomcat versions 8.5 to 11 are vulnerable to a security risk that allows a malicious request to bypass certain security constraints. This could potentially allow an attacker to access unauthorized areas of a website. To fix this issue, update to the latest version of Apache Tomcat.
What to do
- Update tomcat to version 11.0.6.
- Update apache org.apache.tomcat:tomcat-catalina to version 9.0.104.
- Update apache org.apache.tomcat:tomcat-catalina to version 10.1.40.
- Update apache org.apache.tomcat:tomcat-catalina to version 11.0.6.
- Update apache org.apache.tomcat.embed:tomcat-embed-core to version 9.0.104.
- Update apache org.apache.tomcat.embed:tomcat-embed-core to version 10.1.40.
- Update apache org.apache.tomcat.embed:tomcat-embed-core to version 11.0.6.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Bitnami | – | tomcat |
>= 11.0.0, < 11.0.6 Fix: upgrade to 11.0.6
|
| maven | apache | org.apache.tomcat:tomcat-catalina |
>= 9.0.76, <= 9.0.102 >= 10.1.10, < 10.1.40 >= 11.0.0-M2, < 11.0.6 >= 8.5.0, <= 8.5.100 Fix: upgrade to 9.0.104
|
| maven | apache | org.apache.tomcat.embed:tomcat-embed-core |
>= 9.0.76, <= 9.0.102 >= 10.1.10, < 10.1.40 >= 11.0.0-M2, < 11.0.6 >= 8.5.0, <= 8.5.100 Fix: upgrade to 9.0.104
|
| – | apache | tomcat |
>= 9.0.0, < 9.0.104 >= 10.1.0, < 10.1.40 >= 11.0.0, < 11.0.6 cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
Original title
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible
for a specially crafted request ...
Original description
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible
for a specially crafted request to bypass some rewrite rules. If those
rewrite rules effectively enforced security constraints, those
constraints could be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
for a specially crafted request to bypass some rewrite rules. If those
rewrite rules effectively enforced security constraints, those
constraints could be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
ghsa CVSS4.0
2.7
Vulnerability type
CWE-116
CWE-150
- https://nvd.nist.gov/vuln/detail/CVE-2025-31651
- https://lists.apache.org/[email protected]
- http://www.openwall.com/lists/oss-security/2025/04/28/3
- https://github.com/apache/tomcat/commit/066bf6b6a15a4e7e0941d4acf096841165b97098
- https://github.com/apache/tomcat/commit/175dc75fc428930034a6c93fb52f830d955d8e64
- https://github.com/apache/tomcat/commit/ee3ab548e92345eca0cbd1f01649eb36c6f29454
- https://github.com/apache/tomcat/commit/fbecc915a10c5a3d634c5e2c6ced4ff479ce9953
- https://tomcat.apache.org/security-10.html
- https://tomcat.apache.org/security-11.html
- https://tomcat.apache.org/security-9.html
- https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html
- https://github.com/advisories/GHSA-ff77-26x5-69cr
Published: 28 Apr 2025 · Updated: 19 Jul 2026 · First seen: 6 Mar 2026