Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled (CVE-2025-55752)
A directory traversal vulnerability in Apache Tomcat allows attackers to bypass security constraints on sensitive directories such as /WEB-INF/ and /META-INF/ via manipulated rewritten URLs. If the HTTP PUT method is enabled, this can lead to remote code execution by uploading malicious files. The issue affects multiple versions of Apache Tomcat from 8.5.6 through 8.5.100, 9.0.0 through 9.0.108, 10.1.0 through 10.1.44, and 11.0.0 through 11.0.10. The vulnerability was introduced as a regression in a previous fix and has been addressed in later versions. Users are advised to upgrade to fixed versions to mitigate the risk.
AI Analysis
Technical Summary
This vulnerability (CVE-2025-55752) in Apache Tomcat arises from a regression introduced by the fix for bug 60013, where the rewritten URL was normalized before decoding. This flaw allows attackers to manipulate the request URI in rewrite rules that affect query parameters, enabling bypass of security constraints protecting critical directories like /WEB-INF/ and /META-INF/. When the HTTP PUT method is enabled, which is typically restricted to trusted users, attackers could upload malicious files leading to remote code execution. The affected versions include Apache Tomcat 8.5.6 through 8.5.100, 9.0.0 through 9.0.108, 10.1.0 through 10.1.44, and 11.0.0 through 11.0.10. The issue has been fixed in versions 8.5.101 and later, 9.0.109 and later, 10.1.45 and later, and 11.0.11 and later.
Potential Impact
Attackers can bypass security constraints on sensitive directories, potentially accessing or modifying protected resources. If the HTTP PUT method is enabled, this vulnerability can be exploited to upload malicious files, resulting in remote code execution. However, enabling PUT requests is uncommon and typically restricted, reducing the likelihood of exploitation in many environments.
Mitigation Recommendations
A fix is available. Users should upgrade to Apache Tomcat versions 11.0.11 or later, 10.1.45 or later, or 9.0.109 or later to remediate this vulnerability. If upgrading is not immediately possible, ensure that the HTTP PUT method is disabled unless explicitly required and restricted to trusted users. Review rewrite rules to avoid manipulation of query parameters that could lead to URI bypass.
Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled (CVE-2025-55752)
Description
A directory traversal vulnerability in Apache Tomcat allows attackers to bypass security constraints on sensitive directories such as /WEB-INF/ and /META-INF/ via manipulated rewritten URLs. If the HTTP PUT method is enabled, this can lead to remote code execution by uploading malicious files. The issue affects multiple versions of Apache Tomcat from 8.5.6 through 8.5.100, 9.0.0 through 9.0.108, 10.1.0 through 10.1.44, and 11.0.0 through 11.0.10. The vulnerability was introduced as a regression in a previous fix and has been addressed in later versions. Users are advised to upgrade to fixed versions to mitigate the risk.
Affected software
pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-55752) in Apache Tomcat arises from a regression introduced by the fix for bug 60013, where the rewritten URL was normalized before decoding. This flaw allows attackers to manipulate the request URI in rewrite rules that affect query parameters, enabling bypass of security constraints protecting critical directories like /WEB-INF/ and /META-INF/. When the HTTP PUT method is enabled, which is typically restricted to trusted users, attackers could upload malicious files leading to remote code execution. The affected versions include Apache Tomcat 8.5.6 through 8.5.100, 9.0.0 through 9.0.108, 10.1.0 through 10.1.44, and 11.0.0 through 11.0.10. The issue has been fixed in versions 8.5.101 and later, 9.0.109 and later, 10.1.45 and later, and 11.0.11 and later.
Potential Impact
Attackers can bypass security constraints on sensitive directories, potentially accessing or modifying protected resources. If the HTTP PUT method is enabled, this vulnerability can be exploited to upload malicious files, resulting in remote code execution. However, enabling PUT requests is uncommon and typically restricted, reducing the likelihood of exploitation in many environments.
Mitigation Recommendations
A fix is available. Users should upgrade to Apache Tomcat versions 11.0.11 or later, 10.1.45 or later, or 9.0.109 or later to remediate this vulnerability. If upgrading is not immediately possible, ensure that the HTTP PUT method is disabled unless explicitly required and restricted to trusted users. Review rewrite rules to avoid manipulation of query parameters that could lead to URI bypass.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2025-55752
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a58b50368715ace43db287c
Added to database: 07/16/2026, 10:40:03 UTC
Last enriched: 09/08/2026, 15:06:19 UTC
Last updated: 09/10/2026, 19:24:57 UTC
Views: 22
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.