Giuseppe,

On 7/21/26 12:51 PM, LAURIA Giuseppe via users wrote:
Unfortunately, this is why our Tomcat now ends up on a security list and 
because it is classified as Critical, it should be solved within a very short 
time even though we are not using it.
And I assume that this will not get any better in the future, but that such 
cases are still often discovered which do not concern us.

Couldn’t there be something better from the Tomcat corner?

The Apache Tomcat team will never be in charge of the opinion registered in the NIST (or any other) report.

As Tim says, the NIST opinion is typically very focused on the "potential worse outcome" while Tomcat's opinion is based upon real-world usage. Yes, if a certain user has a vulnerable configuration then it could be VERY BAD for them.

It's your organization's policy that NIST's opinion is the one that matters. If you trust NIST's opinion with no other information, then you are responsible for the consequences (e.g. requiring an immediate upgrade). If you trust Tomcat's opinion more (or you are allowed to evaluate your own environment and determine your own opinion), then you can de-prioritize the upgrade.

But there is absolutely nothing Tomcat to do to help with the situation you find yourself in.

-chris

-----Ursprüngliche Nachricht-----
Von: Tim Funk <[email protected]>
Gesendet: Dienstag, 21. Juli 2026 18:43
An: Tomcat Users List <[email protected]>
Betreff: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow 
security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?

The NIST score is based on a formula based on various factors. Which is heavily 
weighted to be 'high" in bugs like this.

Here its rated LOW because
- The Valve needs enabled (by default not)
- And used / configured
- And  configured in a way that allows exploit
- And used in an app that has in its application plane security controls that 
could be bypassed

AKA ... A not normal combination of factors.

-Tim

On Tue, Jul 21, 2026 at 12:18 PM LAURIA Giuseppe via users < 
[email protected]> wrote:

Hi Tomcat users.



We are using Tomcat v9.0.119 and are now forced to immediately use
v9.0.120 because the “*Incorrect URL decoding in RewriteValve may
allow security control bypass” *vulnerability in Tomcat is rated 9.1
on NIST which is CRITICAL. ->
https://urldefense.com/v3/__https://nvd.nist.gov/vuln/detail/CVE-2026-
59083__;!!BnkV9pdh5V0!BCo5DKCO7Y_ozhdqL-GoPCyn7LgV9FqlquK_XGZ_bcjMFhOL
cN3GAGMvpAp-KEZa04hNdOQRCQ2UpSzv1om0$



But on the Tomcat security page this vulnerability is rated ‘LOW’.

https://urldefense.com/v3/__https://tomcat.apache.org/security-9.html_
_;!!BnkV9pdh5V0!BCo5DKCO7Y_ozhdqL-GoPCyn7LgV9FqlquK_XGZ_bcjMFhOLcN3GAG
MvpAp-KEZa04hNdOQRCQ2UpcnGSQw6$


Who is wrong ?





We are not using “rewrite Valve” and therefore think we are not affected.

Why there is no detailed explanation on the NIST page that only Tomcat
users *using rewrite Valve* are affected ?




---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]



---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to