PT-2026-81885 · Apache · Apache Tomcat
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 11.0.0-M1 through 11.0.24
Apache Tomcat versions 10.1.0-M1 through 10.1.57
Apache Tomcat versions 9.0.0.M1 through 9.0.120
Apache Tomcat versions 8.5.0 through 8.5.100
Description
An off-by-one error in the rewrite valves occurs when the
[N] flag is used. This causes the rewrite processing to restart at the second rule instead of the first rule.Recommendations
Upgrade Apache Tomcat versions 11.0.0-M1 through 11.0.24 to version 11.0.25.
Upgrade Apache Tomcat versions 10.1.0-M1 through 10.1.57 to version 10.1.58.
Upgrade Apache Tomcat versions 9.0.0.M1 through 9.0.120 to version 9.0.121.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat