CVE-2025-31651 | Apache Tomcat up to 9.0.102/10.1.39/11.0.5 Rewrite Rule escape, meta, or control sequences (EUVD-2025-13626 / Nessus ID 235034)
A vulnerability labeled as problematic has been found in Apache Tomcat up to 9.0.102/10.1.39/11.0.5. Affected by this issue is some unknown functionality of the component Rewrite Rule Handler. Such manipulation leads to improper neutralization of escape, meta, or control sequences.
This vulnerability is listed as CVE-2025-31651. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.