Apache Tomcat: Occasionally open redirect (CVE-2026-25854)
An open redirect vulnerability exists in Apache Tomcat via the LoadBalancerDrainingValve, which can occasionally redirect users to untrusted sites. This affects multiple versions of Apache Tomcat from 8.5.30 through 8.5.100, 9.0.0 through 9.0.115, 10.1.0 through 10.1.52, and 11.0.0 through 11.0.18. Users are advised to upgrade to fixed versions 11.0.20, 10.1.53, or 9.0.116 to resolve the issue.
AI Analysis
Technical Summary
CVE-2026-25854 is an open redirect vulnerability in Apache Tomcat's LoadBalancerDrainingValve component. This vulnerability may cause occasional URL redirection to untrusted external sites. It affects Apache Tomcat versions 8.5.30 through 8.5.100, 9.0.0 through 9.0.115, 10.1.0 through 10.1.52, and 11.0.0 through 11.0.18. The issue is resolved in versions 11.0.20, 10.1.53, and 9.0.116. Other unsupported versions may also be affected but are not explicitly detailed.
Potential Impact
The vulnerability allows occasional redirection of users to untrusted external websites, which could be leveraged for phishing or other social engineering attacks. However, no evidence of active exploitation is reported. The impact is considered medium severity due to the potential for redirecting users without their consent.
Mitigation Recommendations
A patch is available and users should upgrade to Apache Tomcat versions 11.0.20, 10.1.53, or 9.0.116 to remediate this vulnerability. No additional mitigation steps are indicated by the vendor advisory.
Apache Tomcat: Occasionally open redirect (CVE-2026-25854)
Description
An open redirect vulnerability exists in Apache Tomcat via the LoadBalancerDrainingValve, which can occasionally redirect users to untrusted sites. This affects multiple versions of Apache Tomcat from 8.5.30 through 8.5.100, 9.0.0 through 9.0.115, 10.1.0 through 10.1.52, and 11.0.0 through 11.0.18. Users are advised to upgrade to fixed versions 11.0.20, 10.1.53, or 9.0.116 to resolve the issue.
Affected software
pkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-25854 is an open redirect vulnerability in Apache Tomcat's LoadBalancerDrainingValve component. This vulnerability may cause occasional URL redirection to untrusted external sites. It affects Apache Tomcat versions 8.5.30 through 8.5.100, 9.0.0 through 9.0.115, 10.1.0 through 10.1.52, and 11.0.0 through 11.0.18. The issue is resolved in versions 11.0.20, 10.1.53, and 9.0.116. Other unsupported versions may also be affected but are not explicitly detailed.
Potential Impact
The vulnerability allows occasional redirection of users to untrusted external websites, which could be leveraged for phishing or other social engineering attacks. However, no evidence of active exploitation is reported. The impact is considered medium severity due to the potential for redirecting users without their consent.
Mitigation Recommendations
A patch is available and users should upgrade to Apache Tomcat versions 11.0.20, 10.1.53, or 9.0.116 to remediate this vulnerability. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-25854
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a58b4dc68715ace43dae4c7
Added to database: 07/16/2026, 10:39:24 UTC
Last enriched: 09/08/2026, 15:05:51 UTC
Last updated: 09/10/2026, 19:36:53 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.