CVE-2025-31651

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 28, 2025
Updated: May 6, 2025
CWE ID 116

Summary

CVE-2025-31651 is an Improper Neutralization of Escape, Meta, or Control Sequences vulnerability affecting Apache Tomcat. This issue allows a specially crafted request to bypass some rewrite rules for a subset of unlikely configurations, potentially enabling the bypass of security constraints. Apache Tomcat versions 11.0.0-M1 through 11.0.5, 10.1.0-M1 through 10.1.39, and 9.0.0.M1 through 9.0.102 are vulnerable. Users are advised to upgrade to the fixed version [FIXED_VERSION] to address this security concern.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share