Re: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Zdeněk Henek <[email protected]> Wed, 22 Jul 2026 12:47:38 +0000
| Newsgroups | gmane.comp.jakarta.tomcat.user |
|---|---|
| Message-ID | <CAKAD8xZRiJJKbhX9VQYtJwFSrtojw1tL5JQwr14LuqPqTbmGRw@mail.gmail.com> |
Hi Giuseppe, there is paid subscription of Apache Tomcat provided by RedHat. It is called RedHat Jboss Web Server. Details here: https://docs.redhat.com/en/documentation/red_hat_jboss_web_server/5.8 I see here https://access.redhat.com/articles/111723 JWS 5.8.0 contains Apache Tomcat 9.0.87. It looks like these Tomcat versions have backported security issues, but this is just my assumption! I think this may be perfect fit for you. Having slower releases including CVE fixes without other improvements. I don't have experience with JWS but that is what I would expect of paid Apache Tomcat support. Maybe somebody here knows more about RedHat JWS? I think this could be another direction to investigate if your security rules are more restrictive. I don't work for RedHat, I am happy Apache Tomcat user :) Regards, Zdenek Henek On Tue, Jul 21, 2026 at 4:52=E2=80=AFPM LAURIA Giuseppe via users <[email protected]> wrote: > > Thank you very much Tim ! > > Unfortunately, this is why our Tomcat now ends up on a security list and = because it is classified as Critical, it should be solved within a very sho= rt time even though we are not using it. > And I assume that this will not get any better in the future, but that su= ch cases are still often discovered which do not concern us. > > Couldn=E2=80=99t there be something better from the Tomcat corner? > > Best regards. > Giuseppe > > > -----Urspr=C3=BCngliche Nachricht----- > Von: Tim Funk <[email protected]> > Gesendet: Dienstag, 21. Juli 2026 18:43 > An: Tomcat Users List <[email protected]> > Betreff: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValv= e may allow security control bypass" is rated 'Low' on tomcat page but 'Cri= tical' on NIST ? > > The NIST score is based on a formula based on various factors. Which is h= eavily weighted to be 'high" in bugs like this. > > Here its rated LOW because > - The Valve needs enabled (by default not) > - And used / configured > - And configured in a way that allows exploit > - And used in an app that has in its application plane security controls = that could be bypassed > > AKA ... A not normal combination of factors. > > -Tim > > On Tue, Jul 21, 2026 at 12:18=E2=80=AFPM LAURIA Giuseppe via users < user= [email protected]> wrote: > > > Hi Tomcat users. > > > > > > > > We are using Tomcat v9.0.119 and are now forced to immediately use > > v9.0.120 because the =E2=80=9C*Incorrect URL decoding in RewriteValve m= ay > > allow security control bypass=E2=80=9D *vulnerability in Tomcat is rate= d 9.1 > > on NIST which is CRITICAL. -> > > https://urldefense.com/v3/__https://nvd.nist.gov/vuln/detail/CVE-2026- > > 59083__;!!BnkV9pdh5V0!BCo5DKCO7Y_ozhdqL-GoPCyn7LgV9FqlquK_XGZ_bcjMFhOL > > cN3GAGMvpAp-KEZa04hNdOQRCQ2UpSzv1om0$ > > > > > > > > But on the Tomcat security page this vulnerability is rated =E2=80=98LO= W=E2=80=99. > > > > https://urldefense.com/v3/__https://tomcat.apache.org/security-9.html_ > > _;!!BnkV9pdh5V0!BCo5DKCO7Y_ozhdqL-GoPCyn7LgV9FqlquK_XGZ_bcjMFhOLcN3GAG > > MvpAp-KEZa04hNdOQRCQ2UpcnGSQw6$ > > > > > > Who is wrong ? > > > > > > > > > > > > We are not using =E2=80=9Crewrite Valve=E2=80=9D and therefore think we= are not affected. > > > > Why there is no detailed explanation on the NIST page that only Tomcat > > users *using rewrite Valve* are affected ? > > > > > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected]