The NIST score is based on a formula based on various factors. Which is heavily weighted to be 'high" in bugs like this.
Here its rated LOW because - The Valve needs enabled (by default not) - And used / configured - And configured in a way that allows exploit - And used in an app that has in its application plane security controls that could be bypassed AKA ... A not normal combination of factors. -Tim On Tue, Jul 21, 2026 at 12:18 PM LAURIA Giuseppe via users < [email protected]> wrote: > Hi Tomcat users. > > > > We are using Tomcat v9.0.119 and are now forced to immediately use > v9.0.120 because the “*Incorrect URL decoding in RewriteValve may allow > security control bypass” *vulnerability in Tomcat is rated 9.1 on NIST > which is CRITICAL. -> https://nvd.nist.gov/vuln/detail/CVE-2026-59083 > > > > But on the Tomcat security page this vulnerability is rated ‘LOW’. > > https://tomcat.apache.org/security-9.html > > > Who is wrong ? > > > > > > We are not using “rewrite Valve” and therefore think we are not affected. > > Why there is no detailed explanation on the NIST page that only Tomcat > users *using rewrite Valve* are affected ? > > >
