Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
"LAURIA Giuseppe via users" <[email protected]> Tue, 21 Jul 2026 16:17:47 +0000
| Newsgroups | gmane.comp.jakarta.tomcat.user |
|---|---|
| Message-ID | <DU7PR04MB110892CAD6A8C69706F162A1D83C22@DU7PR04MB11089.eurprd04.prod.outlook.com> |
--_004_DU7PR04MB110892CAD6A8C69706F162A1D83C22DU7PR04MB11089eu_ Content-Type: multipart/alternative; boundary="_000_DU7PR04MB110892CAD6A8C69706F162A1D83C22DU7PR04MB11089eu_" --_000_DU7PR04MB110892CAD6A8C69706F162A1D83C22DU7PR04MB11089eu_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Hi Tomcat users. We are using Tomcat v9.0.119 and are now forced to immediately use v9.0.120= because the "Incorrect URL decoding in RewriteValve may allow security con= trol bypass" vulnerability in Tomcat is rated 9.1 on NIST which is CRITICAL= . -> https://nvd.nist.gov/vuln/detail/CVE-2026-59083 But on the Tomcat security page this vulnerability is rated 'LOW'. https://tomcat.apache.org/security-9.html [cid:[email protected]] Who is wrong ? We are not using "rewrite Valve" and therefore think we are not affected. Why there is no detailed explanation on the NIST page that only Tomcat user= s using rewrite Valve are affected ? Can please someone shed some light on this ? Thank you very much. Best regards. Giuseppe --_000_DU7PR04MB110892CAD6A8C69706F162A1D83C22DU7PR04MB11089eu_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr= osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:= //www.w3.org/TR/REC-html40"> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"= > <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)"> <!--[if !mso]><style>v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);} </style><![endif]--><style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Aptos;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0cm; font-size:11.0pt; font-family:"Aptos",sans-serif; mso-ligatures:standardcontextual; mso-fareast-language:EN-US;} a:link, span.MsoHyperlink {mso-style-priority:99; color:#467886; text-decoration:underline;} span.E-MailFormatvorlage18 {mso-style-type:personal-compose; font-family:"Arial",sans-serif; color:windowtext;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt; mso-ligatures:none;} @page WordSection1 {size:612.0pt 792.0pt; margin:70.85pt 70.85pt 2.0cm 70.85pt;} div.WordSection1 {page:WordSection1;} --></style> </head> <body lang=3D"DE-CH" link=3D"#467886" vlink=3D"#96607D" style=3D"word-wrap:= break-word"> <div class=3D"WordSection1"> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif">Hi Tomcat users.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif">We are using Tomcat v9.0.119 and are n= ow forced to immediately use v9.0.120 because the “<b>Incorrect URL d= ecoding in RewriteValve may allow security control bypass” </b>vulnerability in Tomcat is rated 9.1 on NIST which is CRITICAL. -> <= a href=3D"https://nvd.nist.gov/vuln/detail/CVE-2026-59083"> https://nvd.nist.gov/vuln/detail/CVE-2026-59083</a><o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif">But on the Tomcat security page this v= ulnerability is rated ‘LOW’.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif;color:black;mso-ligatures:none"><a href= =3D"https://tomcat.apache.org/security-9.html">https://tomcat.apache.org/se= curity-9.html</a></span><span lang=3D"EN-US" style=3D"font-size:10.0pt;font= -family:"Arial",sans-serif;mso-ligatures:none"><o:p></o:p></span>= </p> <p class=3D"MsoNormal"><span style=3D"mso-ligatures:none"><img border=3D"0"= width=3D"796" height=3D"161" style=3D"width:8.2916in;height:1.677in" id=3D= "Grafik_x0020_1" src=3D"cid:[email protected]"></span><span la= ng=3D"EN-US" style=3D"font-size:10.0pt;font-family:"Arial",sans-s= erif;mso-ligatures:none"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif;mso-ligatures:none">Who is wrong ?<o:p>= </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif;mso-ligatures:none"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif;mso-ligatures:none"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif;mso-ligatures:none">We are not using &#= 8220;rewrite Valve” and therefore think we are not affected.<br> <br> Why there is no detailed explanation on the NIST page that only Tomcat user= s <b>using rewrite Valve</b> are affected ?<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif;mso-ligatures:none"><br> <br> <o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif;mso-ligatures:none">Can please someone = shed some light on this ?<br> <br> Thank you very much.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif;mso-ligatures:none"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif;mso-ligatures:none">Best regards.<o:p><= /o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-= family:"Arial",sans-serif;mso-ligatures:none">Giuseppe<o:p></o:p>= </span></p> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> </body> </html> --_000_DU7PR04MB110892CAD6A8C69706F162A1D83C22DU7PR04MB11089eu_-- --_004_DU7PR04MB110892CAD6A8C69706F162A1D83C22DU7PR04MB11089eu_--