Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
2.1

CVE-2025-55754: Apache Tomcat: Malicious URL Can Manipulate Console and Clipboard

GHSA-vfww-5hm6-hx2j CVE-2025-55754 BIT-tomcat-2025-55754
Summary

Apache Tomcat's logging feature doesn't properly escape special characters in log messages. This allows a malicious URL to potentially trick an administrator into running a command on their computer. To fix this, update to version 11.0.11 or later, 10.1.45 or later, or 9.0.109 or later of Apache Tomcat.

What to do
  • Update apache org.apache.tomcat:tomcat to version 11.0.11.
  • Update apache org.apache.tomcat:tomcat to version 10.1.45.
  • Update apache org.apache.tomcat.embed:tomcat-embed-core to version 11.0.11.
  • Update apache org.apache.tomcat.embed:tomcat-embed-core to version 10.1.45.
  • Update apache org.apache.tomcat:tomcat-catalina to version 11.0.11.
  • Update apache org.apache.tomcat:tomcat-catalina to version 10.1.45.
  • Update apache org.apache.tomcat:tomcat to version 9.0.109.
  • Update apache org.apache.tomcat.embed:tomcat-embed-core to version 9.0.109.
  • Update apache org.apache.tomcat:tomcat-catalina to version 9.0.109.
  • Update tomcat to version 11.0.11.
  • Update org.apache.tomcat:tomcat to version 11.0.11.
  • Update org.apache.tomcat:tomcat to version 10.1.45.
  • Update org.apache.tomcat.embed:tomcat-embed-core to version 11.0.11.
  • Update org.apache.tomcat.embed:tomcat-embed-core to version 10.1.45.
  • Update org.apache.tomcat:tomcat-catalina to version 11.0.11.
  • Update org.apache.tomcat:tomcat-catalina to version 10.1.45.
  • Update org.apache.tomcat:tomcat to version 9.0.109.
  • Update org.apache.tomcat.embed:tomcat-embed-core to version 9.0.109.
  • Update org.apache.tomcat:tomcat-catalina to version 9.0.109.
Affected software
Ecosystem VendorProductAffected versions
maven apache org.apache.tomcat:tomcat >= 11.0.0-M1, < 11.0.11
>= 10.1.0-M1, < 10.1.45
>= 8.5.60, <= 8.5.100
>= 9.0.40, < 9.0.109
Fix: upgrade to 11.0.11
maven apache org.apache.tomcat.embed:tomcat-embed-core >= 11.0.0-M1, < 11.0.11
>= 10.1.0-M1, < 10.1.45
>= 8.5.60, <= 8.5.100
>= 9.0.40, < 9.0.109
Fix: upgrade to 11.0.11
maven apache org.apache.tomcat:tomcat-catalina >= 11.0.0-M1, < 11.0.11
>= 10.1.0-M1, < 10.1.45
>= 8.5.60, <= 8.5.100
>= 9.0.40, < 9.0.109
Fix: upgrade to 11.0.11
apache tomcat >= 8.5.60, <= 8.5.100
>= 9.0.40, < 9.0.109
>= 10.0.0, < 10.0.27
>= 10.1.0, < 10.1.45
>= 11.0.0, < 11.0.11
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
Bitnami tomcat >= 11.0.0, < 11.0.11
Fix: upgrade to 11.0.11
maven org.apache.tomcat:tomcat >= 11.0.0-M1, < 11.0.11
>= 10.1.0-M1, < 10.1.45
>= 8.5.60, <= 8.5.100
>= 9.0.40, < 9.0.109
Fix: upgrade to 11.0.11
maven org.apache.tomcat.embed:tomcat-embed-core >= 11.0.0-M1, < 11.0.11
>= 10.1.0-M1, < 10.1.45
>= 8.5.60, <= 8.5.100
>= 9.0.40, < 9.0.109
Fix: upgrade to 11.0.11
maven org.apache.tomcat:tomcat-catalina >= 11.0.0-M1, < 11.0.11
>= 10.1.0-M1, < 10.1.45
>= 8.5.60, <= 8.5.100
>= 9.0.40, < 9.0.109
Fix: upgrade to 11.0.11
Original title
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
Original description
Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.



This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108.

The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.
ghsa CVSS3.1 9.7
ghsa CVSS4.0 2.1
Vulnerability type
CWE-150
Published: 27 Oct 2025 · Updated: 25 Jun 2026 · First seen: 6 Mar 2026