Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
2.7

CVE-2025-31651: Apache Tomcat: Specially crafted requests can bypass security rules

GHSA-ff77-26x5-69cr CVE-2025-31651 BIT-tomcat-2025-31651 CVE-2025-31651
Summary

Apache Tomcat versions 8.5 to 11 are vulnerable to a security risk that allows a malicious request to bypass certain security constraints. This could potentially allow an attacker to access unauthorized areas of a website. To fix this issue, update to the latest version of Apache Tomcat.

What to do
  • Update tomcat to version 11.0.6.
  • Update apache org.apache.tomcat:tomcat-catalina to version 9.0.104.
  • Update apache org.apache.tomcat:tomcat-catalina to version 10.1.40.
  • Update apache org.apache.tomcat:tomcat-catalina to version 11.0.6.
  • Update apache org.apache.tomcat.embed:tomcat-embed-core to version 9.0.104.
  • Update apache org.apache.tomcat.embed:tomcat-embed-core to version 10.1.40.
  • Update apache org.apache.tomcat.embed:tomcat-embed-core to version 11.0.6.
Affected software
Ecosystem VendorProductAffected versions
Bitnami tomcat >= 11.0.0, < 11.0.6
Fix: upgrade to 11.0.6
maven apache org.apache.tomcat:tomcat-catalina >= 9.0.76, <= 9.0.102
>= 10.1.10, < 10.1.40
>= 11.0.0-M2, < 11.0.6
>= 8.5.0, <= 8.5.100
Fix: upgrade to 9.0.104
maven apache org.apache.tomcat.embed:tomcat-embed-core >= 9.0.76, <= 9.0.102
>= 10.1.10, < 10.1.40
>= 11.0.0-M2, < 11.0.6
>= 8.5.0, <= 8.5.100
Fix: upgrade to 9.0.104
apache tomcat >= 9.0.0, < 9.0.104
>= 10.1.0, < 10.1.40
>= 11.0.0, < 11.0.6
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
Original title
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request ...
Original description
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible
for a specially crafted request to bypass some rewrite rules. If those
rewrite rules effectively enforced security constraints, those
constraints could be bypassed.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.


Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
ghsa CVSS4.0 2.7
Vulnerability type
CWE-116
CWE-150
Published: 28 Apr 2025 · Updated: 19 Jul 2026 · First seen: 6 Mar 2026