Apache Tomcat: session fixation via rewrite valve (CVE-2025-55668)
A session fixation vulnerability exists in Apache Tomcat via the rewrite valve. This affects Apache Tomcat versions from 11.0.0 through 11.0.7, 10.1.0 through 10.1.41, and 9.0.0 through 9.0.105, with older end-of-life versions potentially also affected. The issue allows an attacker to fixate a session identifier, potentially leading to unauthorized session access. Fixed versions are 11.0.8, 10.1.42, and 9.0.106.
AI Analysis
Technical Summary
CVE-2025-55668 describes a session fixation vulnerability in Apache Tomcat's rewrite valve component. The flaw affects multiple supported branches of Apache Tomcat, specifically versions 11.0.0 to 11.0.7, 10.1.0 to 10.1.41, and 9.0.0 to 9.0.105. The vulnerability allows an attacker to set or fixate a session ID, which can be used to hijack a user's session. The vendor has addressed this issue in Apache Tomcat versions 11.0.8, 10.1.42, and 9.0.106. Users are advised to upgrade to these fixed versions to mitigate the risk.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to fixate a session identifier, potentially enabling unauthorized access to a victim's session. This can lead to session hijacking or impersonation within affected Apache Tomcat applications. The severity is assessed as medium based on the potential impact on session management security.
Mitigation Recommendations
A fix is available. Users should upgrade affected Apache Tomcat installations to versions 11.0.8, 10.1.42, or 9.0.106 as these versions contain the official fix for this session fixation vulnerability. No additional mitigations are specified by the vendor advisory.
Apache Tomcat: session fixation via rewrite valve (CVE-2025-55668)
Description
A session fixation vulnerability exists in Apache Tomcat via the rewrite valve. This affects Apache Tomcat versions from 11.0.0 through 11.0.7, 10.1.0 through 10.1.41, and 9.0.0 through 9.0.105, with older end-of-life versions potentially also affected. The issue allows an attacker to fixate a session identifier, potentially leading to unauthorized session access. Fixed versions are 11.0.8, 10.1.42, and 9.0.106.
Affected software
pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-55668 describes a session fixation vulnerability in Apache Tomcat's rewrite valve component. The flaw affects multiple supported branches of Apache Tomcat, specifically versions 11.0.0 to 11.0.7, 10.1.0 to 10.1.41, and 9.0.0 to 9.0.105. The vulnerability allows an attacker to set or fixate a session ID, which can be used to hijack a user's session. The vendor has addressed this issue in Apache Tomcat versions 11.0.8, 10.1.42, and 9.0.106. Users are advised to upgrade to these fixed versions to mitigate the risk.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to fixate a session identifier, potentially enabling unauthorized access to a victim's session. This can lead to session hijacking or impersonation within affected Apache Tomcat applications. The severity is assessed as medium based on the potential impact on session management security.
Mitigation Recommendations
A fix is available. Users should upgrade affected Apache Tomcat installations to versions 11.0.8, 10.1.42, or 9.0.106 as these versions contain the official fix for this session fixation vulnerability. No additional mitigations are specified by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2025-55668
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a58b50368715ace43db2884
Added to database: 07/16/2026, 10:40:03 UTC
Last enriched: 09/08/2026, 15:06:37 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.