Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Tim Funk <[email protected]> Tue, 21 Jul 2026 12:43:09 -0400
| Newsgroups | gmane.comp.jakarta.tomcat.user |
|---|---|
| Message-ID | <CANSu_--PwrA39HmFr7rRwKV6wUT+F0u+sx9zKiDMs+ugLTLh8g@mail.gmail.com> |
--0000000000006f4f8d065721b8e5 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable The NIST score is based on a formula based on various factors. Which is heavily weighted to be 'high" in bugs like this. Here its rated LOW because - The Valve needs enabled (by default not) - And used / configured - And configured in a way that allows exploit - And used in an app that has in its application plane security controls that could be bypassed AKA ... A not normal combination of factors. -Tim On Tue, Jul 21, 2026 at 12:18=E2=80=AFPM LAURIA Giuseppe via users < [email protected]> wrote: > Hi Tomcat users. > > > > We are using Tomcat v9.0.119 and are now forced to immediately use > v9.0.120 because the =E2=80=9C*Incorrect URL decoding in RewriteValve may= allow > security control bypass=E2=80=9D *vulnerability in Tomcat is rated 9.1 on= NIST > which is CRITICAL. -> https://nvd.nist.gov/vuln/detail/CVE-2026-59083 > > > > But on the Tomcat security page this vulnerability is rated =E2=80=98LOW= =E2=80=99. > > https://tomcat.apache.org/security-9.html > > > Who is wrong ? > > > > > > We are not using =E2=80=9Crewrite Valve=E2=80=9D and therefore think we a= re not affected. > > Why there is no detailed explanation on the NIST page that only Tomcat > users *using rewrite Valve* are affected ? > > > --0000000000006f4f8d065721b8e5--