PT-2026-57992 · Apache+1 · Apache Tomcat+1

CVE-2026-59083

·

Publicado

2026-07-07

·

Atualizado

2026-08-19

CVSS v2.0

9.4

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:N
Nome do Software Vulnerável e Versões Afetadas Apache Tomcat versões 11.0.0-M1 through 11.0.23 Apache Tomcat versões 10.1.0-M1 through 10.1.56 Apache Tomcat versões 9.0.0.M1 through 9.0.119 Apache Tomcat versões 8.5.0 through 8.5.100
Description O manuseio inadequado da codificação de URL (Codificação Hexadecimal) no rewrite valve permite a ignorar restrições de segurança em algumas configurações. Atividades ofensivas no mundo real visando este problema foram identificadas.
Recommendations Atualizar as versões 11.0.0-M1 through 11.0.23 para 11.0.24. Atualizar as versões 10.1.0-M1 through 10.1.56 para 10.1.57. Atualizar as versões 9.0.0.M1 through 9.0.119 para 9.0.120. No momento, não há informações sobre uma versão mais recente que contenha a correção para as versões 8.5.0 through 8.5.100.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-11888
BIT-TOMCAT-2026-59083
CVE-2026-59083
OESA-2026-3142
OPENSUSE-SU-2026:11399-1
OPENSUSE-SU-2026:11400-1
OPENSUSE-SU-2026:11401-1
OPENSUSE-SU-2026:21486-1
OPENSUSE-SU-2026:21487-1
OPENSUSE-SU-2026:21490-1
RHSA-2026:36872
RHSA-2026:37767
SUSE-SU-2026:3418-1
SUSE-SU-2026:3419-1
SUSE-SU-2026:3430-1
SUSE-SU-2026:3440-1

Produtos afetados

Apache Tomcat
Red Os