https://seclists.org/oss-sec/2025/q2/101: CVE-2025-31651: Apache Tomcat: Bypass of rules in write Valve
Published Apr 28, 2025
·Updated
Affected Software
3 affected components
Apache Tomcat>=11.0.0-M1<=11.0.5
Apache Tomcat>=10.1.0-M1<=10.1.39
Apache Tomcat>=9.0.0.M1<=9.0.102
Frequently Asked Questions
1
What is the severity of CVE-2025-31651?
The severity of CVE-2025-31651 is classified as low.
2
Which versions of Apache Tomcat are affected by CVE-2025-31651?
Affected versions include Apache Tomcat 11.0.0-M1 through 11.0.5, 10.1.0-M1 through 10.1.39, and 9.0.0.M1 through 9.0.102.
3
What does CVE-2025-31651 exploit in Apache Tomcat?
CVE-2025-31651 exploits a vulnerability that allows bypassing of certain rewrite rules in Apache Tomcat.
4
How can I mitigate CVE-2025-31651 in my Apache Tomcat installation?
To mitigate CVE-2025-31651, upgrade your Apache Tomcat installation to a version that exceeds the affected range.
5
What are the potential impacts of CVE-2025-31651 on security?
The potential impact of CVE-2025-31651 includes the possibility of unauthorized access if rewrite rules were meant to enforce security constraints.