Re: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?

Peter Kreuser <[email protected]> Tue, 21 Jul 2026 20:49:28 +0200
Newsgroups gmane.comp.jakarta.tomcat.user
Message-ID <[email protected]>
Guiseppe,

Throwing in my 2cts.

I assume noone here could improve the situation. The rating is already low. S=
o unless your company weighs the rating of the app higher than the NIST rati=
ng, this cannot be solved.
I don't know who is forcing you to update - in my company we could always ge=
t approval of a risk acceptance with a comprehensible explanation.

On a different note, I don't see a reason why you should not be able to upda=
te a minor version.
You would have to update anyways if the CVSS would be a "real" 9.1...

Peter

> Am 21.07.2026 um 20:12 schrieb Sebastian Trost via users <[email protected]=
che.org>:
>=20
> =EF=BB=BFGiuseppe,
>=20
>> On 7/21/26 18:51, LAURIA Giuseppe via users wrote:
>> And I assume that this will not get any better in the future, but that su=
ch cases are still often discovered which do not concern us.
>> Couldn=E2=80=99t there be something better from the Tomcat corner?
> Since this is an open source project I'm sure that suggestions are always w=
elcome.
>=20
> Sebastian
>=20
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]