CVE-2026-59083: Apache Tomcat - Incorrect URL decoding in RewriteValve may allow security control bypass
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat’s rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
References
- www.openwall.com/lists/oss-security/2026/07/14/7
- github.com/advisories/GHSA-hcjr-322h-429r
- github.com/apache/tomcat/commit/f00ab28725a18c7fffda421e9858c27badcac1e4
- lists.apache.org/thread/3g63zos2gkjo5vgnrk8kxmosv47w6wbq
- nvd.nist.gov/vuln/detail/CVE-2026-59083
- tomcat.apache.org/security-10.html
- tomcat.apache.org/security-11.html
- tomcat.apache.org/security-9.html
Code Behaviors & Features
Detect and mitigate CVE-2026-59083 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →