Bug 2369253 (CVE-2025-46701)

Summary: CVE-2025-46701 tomcat: Apache Tomcat: Security constraint bypass for CGI scripts
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aferreir, aogburn, csutherl, dsoumis, jclere, kyoshida, pjindal, plodge, prodsec-dev, rmaucher, szappis
Target Milestone: ---Keywords: Security
Target Release: ---Flags: kyoshida: needinfo? (prodsec-dev)
aogburn: needinfo? (prodsec-dev)
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the CGI servlet component of Apache Tomcat. This vulnerability allows a security constraint bypass via improper handling of case sensitivity in the pathInfo component of a URI mapped to the CGI servlet.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2369402, 2369403    
Bug Blocks:    

Description OSIDB Bzimport 2025-05-29 20:01:14 UTC
Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104.

Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue.

Comment 5 errata-xmlrpc 2026-03-05 20:39:36 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 6.2.0

Via RHSA-2026:2741 https://access.redhat.com/errata/RHSA-2026:2741

Comment 6 errata-xmlrpc 2026-03-05 20:39:48 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 6.2 on RHEL 10
  Red Hat JBoss Web Server 6.2 on RHEL 8
  Red Hat JBoss Web Server 6.2 on RHEL 9

Via RHSA-2026:2740 https://access.redhat.com/errata/RHSA-2026:2740

Comment 7 errata-xmlrpc 2026-05-19 09:04:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:18536 https://access.redhat.com/errata/RHSA-2026:18536

Comment 8 errata-xmlrpc 2026-05-19 09:05:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:18537 https://access.redhat.com/errata/RHSA-2026:18537

Comment 9 errata-xmlrpc 2026-05-19 13:18:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:18916 https://access.redhat.com/errata/RHSA-2026:18916