Hi Tomcat users.

We are using Tomcat v9.0.119 and are now forced to immediately use v9.0.120 
because the "Incorrect URL decoding in RewriteValve may allow security control 
bypass" vulnerability in Tomcat is rated 9.1 on NIST which is CRITICAL. -> 
https://nvd.nist.gov/vuln/detail/CVE-2026-59083

But on the Tomcat security page this vulnerability is rated 'LOW'.
https://tomcat.apache.org/security-9.html
[cid:[email protected]]
Who is wrong ?


We are not using "rewrite Valve" and therefore think we are not affected.

Why there is no detailed explanation on the NIST page that only Tomcat users 
using rewrite Valve are affected ?


Can please someone shed some light on this ?

Thank you very much.

Best regards.
Giuseppe

Reply via email to