PT-2026-81885 · Apache · Apache Tomcat

·

CVE-2026-65927

·

Published

2026-08-25

·

Updated

2026-09-11

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.24 Apache Tomcat versions 10.1.0-M1 through 10.1.57 Apache Tomcat versions 9.0.0.M1 through 9.0.120 Apache Tomcat versions 8.5.0 through 8.5.100
Description An off-by-one error in the rewrite valves occurs when the [N] flag is used. This causes the rewrite processing to restart at the second rule instead of the first rule.
Recommendations Upgrade Apache Tomcat versions 11.0.0-M1 through 11.0.24 to version 11.0.25. Upgrade Apache Tomcat versions 10.1.0-M1 through 10.1.57 to version 10.1.58. Upgrade Apache Tomcat versions 9.0.0.M1 through 9.0.120 to version 9.0.121.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TOMCAT-2026-65927
CVE-2026-65927
OPENSUSE-SU-2026:11759-1
OPENSUSE-SU-2026:11760-1
OPENSUSE-SU-2026:11761-1
OPENSUSE-SU-2026:21810-1
OPENSUSE-SU-2026:21811-1

Affected Products

Apache Tomcat