The NIST score is based on a formula based on various factors. Which is
heavily weighted to be 'high" in bugs like this.

Here its rated LOW because
- The Valve needs enabled (by default not)
- And used / configured
- And  configured in a way that allows exploit
- And used in an app that has in its application plane security controls
that could be bypassed

AKA ... A not normal combination of factors.

-Tim

On Tue, Jul 21, 2026 at 12:18 PM LAURIA Giuseppe via users <
[email protected]> wrote:

> Hi Tomcat users.
>
>
>
> We are using Tomcat v9.0.119 and are now forced to immediately use
> v9.0.120 because the “*Incorrect URL decoding in RewriteValve may allow
> security control bypass” *vulnerability in Tomcat is rated 9.1 on NIST
> which is CRITICAL. -> https://nvd.nist.gov/vuln/detail/CVE-2026-59083
>
>
>
> But on the Tomcat security page this vulnerability is rated ‘LOW’.
>
> https://tomcat.apache.org/security-9.html
>
>
> Who is wrong ?
>
>
>
>
>
> We are not using “rewrite Valve” and therefore think we are not affected.
>
> Why there is no detailed explanation on the NIST page that only Tomcat
> users *using rewrite Valve* are affected ?
>
>
>

Reply via email to