CVE-2026-59083

tomcat: Improper Handling of URL Encoding (Hex Encoding) (CVE-2026-59083)

criticalEPSS 0.4%

Affected

  • bitnami/tomcat 10.1.0..*
  • bitnami/tomcat 11.0.0..*

Description

A flaw was found in Apache Tomcat. This vulnerability, located in the rewrite valve, is due to improper handling of URL encoding (hex encoding). A remote attacker could exploit this to bypass security constraints in certain configurations, potentially gaining unauthorized access or performing actions that should be restricted.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

bitnamitomcat
10.1.011.0.0

Metrics

9.1
Source: nvd-v3
28.9 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
critical
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-15 16:00 UTC
CWE-177

Weakness classes (CWE)

  • CWE-177Variant

    Improper Handling of URL Encoding (Hex Encoding)

    The product does not properly handle when all or part of an input has been URL encoded.

    cwe.mitre.org →

References & sources

Linked advisories