CVE-2026-53404: Apache Tomcat: Bad ornext processing in RewriteValve
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.118-0+deb11u1Fixed in 9.0.70-2Fixed in 9.0.95-1Fixed in 9.0.118-1 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.23 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.56 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.119
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53404?
CVE-2026-53404 has a risk level of 30, indicating a moderate vulnerability.
How do I fix CVE-2026-53404?
To mitigate CVE-2026-53404, upgrade Apache Tomcat to the latest version beyond 11.0.22, 10.1.55, or 9.0.x where the vulnerability is patched.
What versions of Apache Tomcat are affected by CVE-2026-53404?
CVE-2026-53404 impacts Apache Tomcat versions from 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, and others within the 9.0.x series.
What type of vulnerability is CVE-2026-53404?
CVE-2026-53404 is categorized as a control flow implementation vulnerability affecting the RewriteValve component in Apache Tomcat.
What is the impact of CVE-2026-53404 on Apache Tomcat?
The vulnerability can lead to improper condition evaluation in the RewriteValve, potentially causing unintended request processing behavior.