Apache Tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651)
Apache Tomcat contains a vulnerability in its Rewrite Valve that allows bypassing certain rewrite rules under specific, unlikely configurations. This flaw could enable attackers to circumvent security constraints enforced by these rules. The issue affects multiple Tomcat versions including 8.5.x, 9.0.x, 10.1.x, and 11.0.x series. A patch is available and users are advised to upgrade to fixed versions to mitigate the risk.
AI Analysis
Technical Summary
CVE-2025-31651 describes an improper neutralization vulnerability in Apache Tomcat's Rewrite Valve. For a subset of unlikely rewrite rule configurations, specially crafted requests could bypass some rewrite rules, potentially allowing attackers to circumvent security constraints that rely on those rules. The affected versions include Apache Tomcat from 11.0.0 through 11.0.5, 10.1.0 through 10.1.39, 9.0.0 through 9.0.102, and 8.5.0 through 8.5.100 (EOL). The vulnerability is addressed in later versions, and users are recommended to upgrade accordingly. The vendor advisory from Ubuntu confirms the issue and indicates that fixes are available via standard system updates or Ubuntu Pro Extended Security Maintenance (ESM) for certain LTS releases.
Potential Impact
If exploited, this vulnerability could allow an attacker to bypass security constraints enforced by rewrite rules in Apache Tomcat, potentially leading to unauthorized access or privilege escalation depending on the specific security policies implemented via those rules. No known exploits are reported in the wild at this time.
Mitigation Recommendations
A fix is available for this vulnerability. Users should upgrade Apache Tomcat to the fixed versions: for example, versions >=11.0.6, >=10.1.40, and >=9.0.104 or later. Ubuntu users can apply security updates via standard system updates or use Ubuntu Pro with Extended Security Maintenance (ESM) for long-term support releases. Applying these updates will remediate the vulnerability. No additional mitigation steps are indicated by the vendor advisory.
Apache Tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651)
Description
Apache Tomcat contains a vulnerability in its Rewrite Valve that allows bypassing certain rewrite rules under specific, unlikely configurations. This flaw could enable attackers to circumvent security constraints enforced by these rules. The issue affects multiple Tomcat versions including 8.5.x, 9.0.x, 10.1.x, and 11.0.x series. A patch is available and users are advised to upgrade to fixed versions to mitigate the risk.
Affected software
pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm3?arch=source&distro=esm-apps/nobleRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-31651 describes an improper neutralization vulnerability in Apache Tomcat's Rewrite Valve. For a subset of unlikely rewrite rule configurations, specially crafted requests could bypass some rewrite rules, potentially allowing attackers to circumvent security constraints that rely on those rules. The affected versions include Apache Tomcat from 11.0.0 through 11.0.5, 10.1.0 through 10.1.39, 9.0.0 through 9.0.102, and 8.5.0 through 8.5.100 (EOL). The vulnerability is addressed in later versions, and users are recommended to upgrade accordingly. The vendor advisory from Ubuntu confirms the issue and indicates that fixes are available via standard system updates or Ubuntu Pro Extended Security Maintenance (ESM) for certain LTS releases.
Potential Impact
If exploited, this vulnerability could allow an attacker to bypass security constraints enforced by rewrite rules in Apache Tomcat, potentially leading to unauthorized access or privilege escalation depending on the specific security policies implemented via those rules. No known exploits are reported in the wild at this time.
Mitigation Recommendations
A fix is available for this vulnerability. Users should upgrade Apache Tomcat to the fixed versions: for example, versions >=11.0.6, >=10.1.40, and >=9.0.104 or later. Ubuntu users can apply security updates via standard system updates or use Ubuntu Pro with Extended Security Maintenance (ESM) for long-term support releases. Applying these updates will remediate the vulnerability. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2025-31651
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a58b50b68715ace43db2e58
Added to database: 07/16/2026, 10:40:11 UTC
Last enriched: 09/08/2026, 15:08:50 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 39
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.