CVE-2026-59083: Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.24 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.57 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.120
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59083?
CVE-2026-59083 has a risk rating of 56, indicating a potentially serious security issue.
How do I fix CVE-2026-59083?
To fix CVE-2026-59083, update Apache Tomcat to version 11.0.24 or higher, 10.1.57 or higher, 9.0.120 or higher, or 8.5.84 or higher.
What impact does CVE-2026-59083 have on Apache Tomcat?
CVE-2026-59083 allows for a security control bypass due to incorrect URL decoding in the RewriteValve.
Which versions of Apache Tomcat are affected by CVE-2026-59083?
CVE-2026-59083 affects Apache Tomcat versions from 11.0.0-M1 through 11.0.23, 10.1.0-M1 through 10.1.56, 9.0.0.M1 through 9.0.119, and from 8.5.0 onwards.
How can I determine if my Apache Tomcat installation is vulnerable to CVE-2026-59083?
Check your Apache Tomcat version against the affected versions listed in CVE-2026-59083 to determine vulnerability.