Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
2.1
CVE-2025-55754: Apache Tomcat: Malicious URL Can Manipulate Console and Clipboard
GHSA-vfww-5hm6-hx2j
CVE-2025-55754
BIT-tomcat-2025-55754
Summary
Apache Tomcat's logging feature doesn't properly escape special characters in log messages. This allows a malicious URL to potentially trick an administrator into running a command on their computer. To fix this, update to version 11.0.11 or later, 10.1.45 or later, or 9.0.109 or later of Apache Tomcat.
What to do
- Update apache org.apache.tomcat:tomcat to version 11.0.11.
- Update apache org.apache.tomcat:tomcat to version 10.1.45.
- Update apache org.apache.tomcat.embed:tomcat-embed-core to version 11.0.11.
- Update apache org.apache.tomcat.embed:tomcat-embed-core to version 10.1.45.
- Update apache org.apache.tomcat:tomcat-catalina to version 11.0.11.
- Update apache org.apache.tomcat:tomcat-catalina to version 10.1.45.
- Update apache org.apache.tomcat:tomcat to version 9.0.109.
- Update apache org.apache.tomcat.embed:tomcat-embed-core to version 9.0.109.
- Update apache org.apache.tomcat:tomcat-catalina to version 9.0.109.
- Update tomcat to version 11.0.11.
- Update org.apache.tomcat:tomcat to version 11.0.11.
- Update org.apache.tomcat:tomcat to version 10.1.45.
- Update org.apache.tomcat.embed:tomcat-embed-core to version 11.0.11.
- Update org.apache.tomcat.embed:tomcat-embed-core to version 10.1.45.
- Update org.apache.tomcat:tomcat-catalina to version 11.0.11.
- Update org.apache.tomcat:tomcat-catalina to version 10.1.45.
- Update org.apache.tomcat:tomcat to version 9.0.109.
- Update org.apache.tomcat.embed:tomcat-embed-core to version 9.0.109.
- Update org.apache.tomcat:tomcat-catalina to version 9.0.109.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| maven | apache | org.apache.tomcat:tomcat |
>= 11.0.0-M1, < 11.0.11 >= 10.1.0-M1, < 10.1.45 >= 8.5.60, <= 8.5.100 >= 9.0.40, < 9.0.109 Fix: upgrade to 11.0.11
|
| maven | apache | org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.11 >= 10.1.0-M1, < 10.1.45 >= 8.5.60, <= 8.5.100 >= 9.0.40, < 9.0.109 Fix: upgrade to 11.0.11
|
| maven | apache | org.apache.tomcat:tomcat-catalina |
>= 11.0.0-M1, < 11.0.11 >= 10.1.0-M1, < 10.1.45 >= 8.5.60, <= 8.5.100 >= 9.0.40, < 9.0.109 Fix: upgrade to 11.0.11
|
| – | apache | tomcat |
>= 8.5.60, <= 8.5.100 >= 9.0.40, < 9.0.109 >= 10.0.0, < 10.0.27 >= 10.1.0, < 10.1.45 >= 11.0.0, < 11.0.11 cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
| Bitnami | – | tomcat |
>= 11.0.0, < 11.0.11 Fix: upgrade to 11.0.11
|
| maven | – | org.apache.tomcat:tomcat |
>= 11.0.0-M1, < 11.0.11 >= 10.1.0-M1, < 10.1.45 >= 8.5.60, <= 8.5.100 >= 9.0.40, < 9.0.109 Fix: upgrade to 11.0.11
|
| maven | – | org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.11 >= 10.1.0-M1, < 10.1.45 >= 8.5.60, <= 8.5.100 >= 9.0.40, < 9.0.109 Fix: upgrade to 11.0.11
|
| maven | – | org.apache.tomcat:tomcat-catalina |
>= 11.0.0-M1, < 11.0.11 >= 10.1.0-M1, < 10.1.45 >= 8.5.60, <= 8.5.100 >= 9.0.40, < 9.0.109 Fix: upgrade to 11.0.11
|
Original title
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
Original description
Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.
ghsa CVSS3.1
9.7
ghsa CVSS4.0
2.1
Vulnerability type
CWE-150
- https://nvd.nist.gov/vuln/detail/CVE-2025-55754
- https://lists.apache.org/thread/j7w54hqbkfcn0xb9xy0wnx8w5nymcbqd
- https://github.com/apache/tomcat/commit/138d7f5cfaae683078948303333c080e6faa75d2
- https://github.com/apache/tomcat/commit/5a3db092982c0c58d4855304167ee757fe5e79bb
- https://github.com/apache/tomcat/commit/a03cabf3a36a42d27d8d997ed31f034f50ba6cd5
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.45
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.11
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.109
- http://www.openwall.com/lists/oss-security/2025/10/27/5
- https://github.com/advisories/GHSA-vfww-5hm6-hx2j
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html URL
Published: 27 Oct 2025 · Updated: 25 Jun 2026 · First seen: 6 Mar 2026