Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?

"LAURIA Giuseppe via users" <[email protected]> Tue, 21 Jul 2026 16:17:47 +0000
Newsgroups gmane.comp.jakarta.tomcat.user
Message-ID <DU7PR04MB110892CAD6A8C69706F162A1D83C22@DU7PR04MB11089.eurprd04.prod.outlook.com>
--_004_DU7PR04MB110892CAD6A8C69706F162A1D83C22DU7PR04MB11089eu_
Content-Type: multipart/alternative;
	boundary="_000_DU7PR04MB110892CAD6A8C69706F162A1D83C22DU7PR04MB11089eu_"

--_000_DU7PR04MB110892CAD6A8C69706F162A1D83C22DU7PR04MB11089eu_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi Tomcat users.

We are using Tomcat v9.0.119 and are now forced to immediately use v9.0.120=
 because the "Incorrect URL decoding in RewriteValve may allow security con=
trol bypass" vulnerability in Tomcat is rated 9.1 on NIST which is CRITICAL=
. -> https://nvd.nist.gov/vuln/detail/CVE-2026-59083

But on the Tomcat security page this vulnerability is rated 'LOW'.
https://tomcat.apache.org/security-9.html
[cid:[email protected]]
Who is wrong ?


We are not using "rewrite Valve" and therefore think we are not affected.

Why there is no detailed explanation on the NIST page that only Tomcat user=
s using rewrite Valve are affected ?


Can please someone shed some light on this ?

Thank you very much.

Best regards.
Giuseppe


--_000_DU7PR04MB110892CAD6A8C69706F162A1D83C22DU7PR04MB11089eu_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	font-size:11.0pt;
	font-family:"Aptos",sans-serif;
	mso-ligatures:standardcontextual;
	mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#467886;
	text-decoration:underline;}
span.E-MailFormatvorlage18
	{mso-style-type:personal-compose;
	font-family:"Arial",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;
	mso-ligatures:none;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 70.85pt 2.0cm 70.85pt;}
div.WordSection1
	{page:WordSection1;}
--></style>
</head>
<body lang=3D"DE-CH" link=3D"#467886" vlink=3D"#96607D" style=3D"word-wrap:=
break-word">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif">Hi Tomcat users.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif">We are using Tomcat v9.0.119 and are n=
ow forced to immediately use v9.0.120 because the &#8220;<b>Incorrect URL d=
ecoding in RewriteValve may allow security control bypass&#8221;
</b>vulnerability in Tomcat is rated 9.1 on NIST which is CRITICAL. -&gt; <=
a href=3D"https://nvd.nist.gov/vuln/detail/CVE-2026-59083">
https://nvd.nist.gov/vuln/detail/CVE-2026-59083</a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif">But on the Tomcat security page this v=
ulnerability is rated &#8216;LOW&#8217;.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif;color:black;mso-ligatures:none"><a href=
=3D"https://tomcat.apache.org/security-9.html">https://tomcat.apache.org/se=
curity-9.html</a></span><span lang=3D"EN-US" style=3D"font-size:10.0pt;font=
-family:&quot;Arial&quot;,sans-serif;mso-ligatures:none"><o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span style=3D"mso-ligatures:none"><img border=3D"0"=
 width=3D"796" height=3D"161" style=3D"width:8.2916in;height:1.677in" id=3D=
"Grafik_x0020_1" src=3D"cid:[email protected]"></span><span la=
ng=3D"EN-US" style=3D"font-size:10.0pt;font-family:&quot;Arial&quot;,sans-s=
erif;mso-ligatures:none"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif;mso-ligatures:none">Who is wrong ?<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif;mso-ligatures:none"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif;mso-ligatures:none"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif;mso-ligatures:none">We are not using &#=
8220;rewrite Valve&#8221; and therefore think we are not affected.<br>
<br>
Why there is no detailed explanation on the NIST page that only Tomcat user=
s <b>using rewrite Valve</b> are affected ?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif;mso-ligatures:none"><br>
<br>
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif;mso-ligatures:none">Can please someone =
shed some light on this ?<br>
<br>
Thank you very much.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif;mso-ligatures:none"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif;mso-ligatures:none">Best regards.<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,sans-serif;mso-ligatures:none">Giuseppe<o:p></o:p>=
</span></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>

--_000_DU7PR04MB110892CAD6A8C69706F162A1D83C22DU7PR04MB11089eu_--

--_004_DU7PR04MB110892CAD6A8C69706F162A1D83C22DU7PR04MB11089eu_--