Thank you very much Mark to point that out.

Best regards.
Giuseppe

-----Ursprüngliche Nachricht-----
Von: Mark Thomas <[email protected]> 
Gesendet: Dienstag, 21. Juli 2026 21:04
An: [email protected]
Betreff: [EXTERNAL] Re: AW: Re: Why tomcat "Incorrect URL decoding in 
RewriteValve may allow security control bypass" is rated 'Low' on tomcat page 
but 'Critical' on NIST ?

On 21/07/2026 17:51, LAURIA Giuseppe via users wrote:
> Thank you very much Tim !
> 
> Unfortunately, this is why our Tomcat now ends up on a security list and 
> because it is classified as Critical, it should be solved within a very short 
> time even though we are not using it.
> And I assume that this will not get any better in the future, but that such 
> cases are still often discovered which do not concern us.
> 
> Couldn’t there be something better from the Tomcat corner?

Like what exactly? We have already rated this issue as low.

If you have issues with the process your employer is following for when to 
apply security fixes then you need to raise those issues with your employer. We 
can't solve them for you.

If you, or your employer, have issues with NIST over stating the severity of a 
CVE then take it up with NIST. Or choose to use a more appropriate information 
source for your circumstances. Again, we have no control over the decisions you 
make.

As LLMs uncover more edge case bugs, this scenario is only going to become more 
frequent. It it is causing you issues now, I'd strongly recommend taking steps 
to address those issues sooner rather than later.

Mark


> 
> Best regards.
> Giuseppe
> 
> 
> -----Ursprüngliche Nachricht-----
> Von: Tim Funk <[email protected]>
> Gesendet: Dienstag, 21. Juli 2026 18:43
> An: Tomcat Users List <[email protected]>
> Betreff: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve 
> may allow security control bypass" is rated 'Low' on tomcat page but 
> 'Critical' on NIST ?
> 
> The NIST score is based on a formula based on various factors. Which is 
> heavily weighted to be 'high" in bugs like this.
> 
> Here its rated LOW because
> - The Valve needs enabled (by default not)
> - And used / configured
> - And  configured in a way that allows exploit
> - And used in an app that has in its application plane security 
> controls that could be bypassed
> 
> AKA ... A not normal combination of factors.
> 
> -Tim
> 
> On Tue, Jul 21, 2026 at 12:18 PM LAURIA Giuseppe via users < 
> [email protected]> wrote:
> 
>> Hi Tomcat users.
>>
>>
>>
>> We are using Tomcat v9.0.119 and are now forced to immediately use
>> v9.0.120 because the “*Incorrect URL decoding in RewriteValve may 
>> allow security control bypass” *vulnerability in Tomcat is rated 9.1 
>> on NIST which is CRITICAL. ->
>> https://urldefense.com/v3/__https://nvd.nist.gov/vuln/detail/CVE-2026
>> - 
>> 59083__;!!BnkV9pdh5V0!BCo5DKCO7Y_ozhdqL-GoPCyn7LgV9FqlquK_XGZ_bcjMFhO
>> L cN3GAGMvpAp-KEZa04hNdOQRCQ2UpSzv1om0$
>>
>>
>>
>> But on the Tomcat security page this vulnerability is rated ‘LOW’.
>>
>> https://urldefense.com/v3/__https://tomcat.apache.org/security-9.html
>> _ 
>> _;!!BnkV9pdh5V0!BCo5DKCO7Y_ozhdqL-GoPCyn7LgV9FqlquK_XGZ_bcjMFhOLcN3GA
>> G
>> MvpAp-KEZa04hNdOQRCQ2UpcnGSQw6$
>>
>>
>> Who is wrong ?
>>
>>
>>
>>
>>
>> We are not using “rewrite Valve” and therefore think we are not affected.
>>
>> Why there is no detailed explanation on the NIST page that only 
>> Tomcat users *using rewrite Valve* are affected ?
>>
>>
>>
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
> 


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to