Bug 2499917 (CVE-2026-59083)

Summary: CVE-2026-59083 tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: csutherl, dsoumis, jclere, jwon, pjindal, plodge, rhel-process-autobot, rmaucher, szappis, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Apache Tomcat. This vulnerability, located in the rewrite valve, is due to improper handling of URL encoding (hex encoding). A remote attacker could exploit this to bypass security constraints in certain configurations, potentially gaining unauthorized access or performing actions that should be restricted.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2508527    
Bug Blocks:    

Description OSIDB Bzimport 2026-07-14 09:01:28 UTC
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.

Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

Comment 3 errata-xmlrpc 2026-08-05 13:11:45 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 7.0.1

Via RHSA-2026:49952 https://access.redhat.com/errata/RHSA-2026:49952

Comment 4 errata-xmlrpc 2026-08-05 13:12:34 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 7.0 on RHEL 10
  Red Hat JBoss Web Server 7.0 on RHEL 8
  Red Hat JBoss Web Server 7.0 on RHEL 9

Via RHSA-2026:49951 https://access.redhat.com/errata/RHSA-2026:49951