CVE-2025-31651
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 28, 2025
Updated: May 6, 2025
CWE ID 116
Summary
CVE-2025-31651 is an Improper Neutralization of Escape, Meta, or Control Sequences vulnerability affecting Apache Tomcat. This issue allows a specially crafted request to bypass some rewrite rules for a subset of unlikely configurations, potentially enabling the bypass of security constraints. Apache Tomcat versions 11.0.0-M1 through 11.0.5, 10.1.0-M1 through 10.1.39, and 9.0.0.M1 through 9.0.102 are vulnerable. Users are advised to upgrade to the fixed version [FIXED_VERSION] to address this security concern.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Apache Tomcat
Affected Vendors
- Apache