Apache Tomcat: Bad ornext processing in RewriteValve (CVE-2026-53404)
CVE-2026-53404 is a vulnerability in Apache Tomcat's RewriteValve component where incorrect control flow causes subsequent non-OR conditions in an OR chain to be skipped if the first condition matches. This flaw affects multiple Apache Tomcat versions across major branches 8.5, 9.0, 10.1, and 11.0. The issue can lead to bypassing rewrite rules, potentially resulting in unauthorized access. Official patches are available in Apache Tomcat versions 11.0.23, 10.1.56, and 9.0.119. Both Ubuntu and Red Hat have released advisories confirming the vulnerability and providing fixed package versions. No known exploits in the wild have been reported to date.
AI Analysis
Technical Summary
Apache Tomcat contains a control flow vulnerability (CVE-2026-53404) in the RewriteValve component. The flaw causes the rewrite valve to incorrectly skip evaluation of subsequent non-OR conditions in an OR chain if the first condition matches, leading to unexpected rule processing. This can allow an attacker to bypass rewrite rules and gain unauthorized access under certain configurations. The vulnerability affects Apache Tomcat versions from 8.5.0 through 8.5.100, 9.0.0 through 9.0.118, 10.1.0 through 10.1.55, and 11.0.0 through 11.0.22. Vendor advisories from Ubuntu and Red Hat confirm the issue and provide fixed versions. Users are advised to upgrade to Apache Tomcat 11.0.23, 10.1.56, or 9.0.119 or apply vendor patches accordingly.
Potential Impact
The vulnerability allows bypassing of rewrite rules in Apache Tomcat's RewriteValve, potentially resulting in unauthorized access to resources that should be protected by these rules. This could weaken security controls relying on rewrite rules for access restrictions. There are no reports of active exploitation in the wild. The impact is considered high due to the potential for unauthorized access.
Mitigation Recommendations
A fix is available. Users should upgrade affected Apache Tomcat installations to versions 11.0.23, 10.1.56, or 9.0.119 or later. Ubuntu and Red Hat have released security advisories with updated package versions that address this vulnerability. Applying these vendor-provided patches or updates will remediate the issue. No additional mitigation steps are indicated by the vendor advisories.
Apache Tomcat: Bad ornext processing in RewriteValve (CVE-2026-53404)
Description
CVE-2026-53404 is a vulnerability in Apache Tomcat's RewriteValve component where incorrect control flow causes subsequent non-OR conditions in an OR chain to be skipped if the first condition matches. This flaw affects multiple Apache Tomcat versions across major branches 8.5, 9.0, 10.1, and 11.0. The issue can lead to bypassing rewrite rules, potentially resulting in unauthorized access. Official patches are available in Apache Tomcat versions 11.0.23, 10.1.56, and 9.0.119. Both Ubuntu and Red Hat have released advisories confirming the vulnerability and providing fixed package versions. No known exploits in the wild have been reported to date.
Affected software
pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache Tomcat contains a control flow vulnerability (CVE-2026-53404) in the RewriteValve component. The flaw causes the rewrite valve to incorrectly skip evaluation of subsequent non-OR conditions in an OR chain if the first condition matches, leading to unexpected rule processing. This can allow an attacker to bypass rewrite rules and gain unauthorized access under certain configurations. The vulnerability affects Apache Tomcat versions from 8.5.0 through 8.5.100, 9.0.0 through 9.0.118, 10.1.0 through 10.1.55, and 11.0.0 through 11.0.22. Vendor advisories from Ubuntu and Red Hat confirm the issue and provide fixed versions. Users are advised to upgrade to Apache Tomcat 11.0.23, 10.1.56, or 9.0.119 or apply vendor patches accordingly.
Potential Impact
The vulnerability allows bypassing of rewrite rules in Apache Tomcat's RewriteValve, potentially resulting in unauthorized access to resources that should be protected by these rules. This could weaken security controls relying on rewrite rules for access restrictions. There are no reports of active exploitation in the wild. The impact is considered high due to the potential for unauthorized access.
Mitigation Recommendations
A fix is available. Users should upgrade affected Apache Tomcat installations to versions 11.0.23, 10.1.56, or 9.0.119 or later. Ubuntu and Red Hat have released security advisories with updated package versions that address this vulnerability. Applying these vendor-provided patches or updates will remediate the issue. No additional mitigation steps are indicated by the vendor advisories.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-53404
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a58b47c68715ace43d9ea02
Added to database: 07/16/2026, 10:37:48 UTC
Last enriched: 09/08/2026, 15:03:28 UTC
Last updated: 09/14/2026, 22:01:35 UTC
Views: 38
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.