On 21/07/2026 17:51, LAURIA Giuseppe via users wrote:
Thank you very much Tim !
Unfortunately, this is why our Tomcat now ends up on a security list and
because it is classified as Critical, it should be solved within a very short
time even though we are not using it.
And I assume that this will not get any better in the future, but that such
cases are still often discovered which do not concern us.
Couldn’t there be something better from the Tomcat corner?
Like what exactly? We have already rated this issue as low.
If you have issues with the process your employer is following for when
to apply security fixes then you need to raise those issues with your
employer. We can't solve them for you.
If you, or your employer, have issues with NIST over stating the
severity of a CVE then take it up with NIST. Or choose to use a more
appropriate information source for your circumstances. Again, we have no
control over the decisions you make.
As LLMs uncover more edge case bugs, this scenario is only going to
become more frequent. It it is causing you issues now, I'd strongly
recommend taking steps to address those issues sooner rather than later.
Mark
Best regards.
Giuseppe
-----Ursprüngliche Nachricht-----
Von: Tim Funk <[email protected]>
Gesendet: Dienstag, 21. Juli 2026 18:43
An: Tomcat Users List <[email protected]>
Betreff: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow
security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
The NIST score is based on a formula based on various factors. Which is heavily
weighted to be 'high" in bugs like this.
Here its rated LOW because
- The Valve needs enabled (by default not)
- And used / configured
- And configured in a way that allows exploit
- And used in an app that has in its application plane security controls that
could be bypassed
AKA ... A not normal combination of factors.
-Tim
On Tue, Jul 21, 2026 at 12:18 PM LAURIA Giuseppe via users <
[email protected]> wrote:
Hi Tomcat users.
We are using Tomcat v9.0.119 and are now forced to immediately use
v9.0.120 because the “*Incorrect URL decoding in RewriteValve may
allow security control bypass” *vulnerability in Tomcat is rated 9.1
on NIST which is CRITICAL. ->
https://urldefense.com/v3/__https://nvd.nist.gov/vuln/detail/CVE-2026-
59083__;!!BnkV9pdh5V0!BCo5DKCO7Y_ozhdqL-GoPCyn7LgV9FqlquK_XGZ_bcjMFhOL
cN3GAGMvpAp-KEZa04hNdOQRCQ2UpSzv1om0$
But on the Tomcat security page this vulnerability is rated ‘LOW’.
https://urldefense.com/v3/__https://tomcat.apache.org/security-9.html_
_;!!BnkV9pdh5V0!BCo5DKCO7Y_ozhdqL-GoPCyn7LgV9FqlquK_XGZ_bcjMFhOLcN3GAG
MvpAp-KEZa04hNdOQRCQ2UpcnGSQw6$
Who is wrong ?
We are not using “rewrite Valve” and therefore think we are not affected.
Why there is no detailed explanation on the NIST page that only Tomcat
users *using rewrite Valve* are affected ?
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]