Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?

Tim Funk <[email protected]> Tue, 21 Jul 2026 12:43:09 -0400
Newsgroups gmane.comp.jakarta.tomcat.user
Message-ID <CANSu_--PwrA39HmFr7rRwKV6wUT+F0u+sx9zKiDMs+ugLTLh8g@mail.gmail.com>
--0000000000006f4f8d065721b8e5
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

The NIST score is based on a formula based on various factors. Which is
heavily weighted to be 'high" in bugs like this.

Here its rated LOW because
- The Valve needs enabled (by default not)
- And used / configured
- And  configured in a way that allows exploit
- And used in an app that has in its application plane security controls
that could be bypassed

AKA ... A not normal combination of factors.

-Tim

On Tue, Jul 21, 2026 at 12:18=E2=80=AFPM LAURIA Giuseppe via users <
[email protected]> wrote:

> Hi Tomcat users.
>
>
>
> We are using Tomcat v9.0.119 and are now forced to immediately use
> v9.0.120 because the =E2=80=9C*Incorrect URL decoding in RewriteValve may=
 allow
> security control bypass=E2=80=9D *vulnerability in Tomcat is rated 9.1 on=
 NIST
> which is CRITICAL. -> https://nvd.nist.gov/vuln/detail/CVE-2026-59083
>
>
>
> But on the Tomcat security page this vulnerability is rated =E2=80=98LOW=
=E2=80=99.
>
> https://tomcat.apache.org/security-9.html
>
>
> Who is wrong ?
>
>
>
>
>
> We are not using =E2=80=9Crewrite Valve=E2=80=9D and therefore think we a=
re not affected.
>
> Why there is no detailed explanation on the NIST page that only Tomcat
> users *using rewrite Valve* are affected ?
>
>
>

--0000000000006f4f8d065721b8e5--