Apache Tomcat RewriteValve URL Decode Bypass <=11.0.23,<10.1.56,<9.0.119,<8.5.100
CVE-2026-59083 Published on July 14, 2026

Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-59083 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Type

What is a Hex Encoding Vulnerability?

The software does not properly handle when all or part of an input has been URL encoded.

CVE-2026-59083 has been classified to as a Hex Encoding vulnerability or weakness.


Products Associated with CVE-2026-59083

stack.watch emails you whenever new vulnerabilities are published in Apache Tomcat or F5 Networks Tomcat. Just hit a watch button to start following.

 
 

Affected Versions

Apache Software Foundation Apache Tomcat: