Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-59083EXPLOITEDPATCHED
apache · tomcat

Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass

Description

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

Affected Products

VendorProductVersions
apachetomcat11.0.0-M1, 10.1.0-M1, 9.0.0.M1, 8.5.0, 10.1.57, 9.0.120, 11.0.24

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachetomcatcert_advisory90%
ibmqradar siemcert_advisory90%

References

  • https://lists.apache.org/thread/3g63zos2gkjo5vgnrk8kxmosv47w6wbq(vendor-advisory)

Related News (8 articles)

Tier B
CERT-FR10d ago
Multiples vulnérabilités dans les produits IBM (18 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits IBM (11 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR31d ago
Multiples vulnérabilités dans les produits IBM (28 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories31d ago
[NEU] [hoch] IBM QRadar SIEM: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR75d ago
Multiples vulnérabilités dans Apache Tomcat (15 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories75d ago
[NEU] [mittel] Apache Tomcat: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security75d ago
CVE-2026-59083: Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
→ No new info (linked only)
Tier C
VulDB75d ago
CVE-2026-59083 | Apache Tomcat up to 11.0.23/10.1.56/9.0.119/8.5.100 Rewrite Valve encoding error
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
11.0.24
CWECWE-177
PublishedJul 14, 2026
Last enriched74d agov4
Tags
CVE-2026-59083
Trending Score19
Source articles8
Independent4
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-71290
Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
Trending: 45
HIGHCVE-2026-59878
Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Trending: 38
CRITICALCVE-2026-55976
Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url
Trending: 33
CRITICALCVE-2026-49845
Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths
Trending: 27
CRITICALCVE-2026-66713
Apache Axis2/Java: deserialization of untrusted Data
Trending: 20

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: severity, patchAvailable
Jul 14, 2026
Updated: description, severity, activelyExploited, tags
Jul 14, 2026
Actively Exploited
Jul 14, 2026
Patch Available
Jul 14, 2026
Updated: affectedVersions
Jul 15, 2026

Version History

v4
Last enriched 74d ago
v4Tier B74d ago

Updated affected versions to include 10.1.57, 9.0.120, and 11.0.24, and confirmed that the patch is now available.

affectedVersions
via CERT-FR
v3Tier C75d ago

Updated severity to HIGH, added CVE-2026-59083, and clarified exploit availability.

descriptionseverityactivelyExploitedtags
via VulDB
v2Tier C75d ago

Updated severity from NONE to LOW and specified the fixed version as 11.0.24.

severitypatchAvailable
via oss-security
v175d ago

Initial creation