Hi Tomcat users. We are using Tomcat v9.0.119 and are now forced to immediately use v9.0.120 because the "Incorrect URL decoding in RewriteValve may allow security control bypass" vulnerability in Tomcat is rated 9.1 on NIST which is CRITICAL. -> https://nvd.nist.gov/vuln/detail/CVE-2026-59083
But on the Tomcat security page this vulnerability is rated 'LOW'. https://tomcat.apache.org/security-9.html [cid:[email protected]] Who is wrong ? We are not using "rewrite Valve" and therefore think we are not affected. Why there is no detailed explanation on the NIST page that only Tomcat users using rewrite Valve are affected ? Can please someone shed some light on this ? Thank you very much. Best regards. Giuseppe
