CVE-2026-25854

Source
https://cve.org/CVERecord?id=CVE-2026-25854
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-25854.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-25854
Aliases
Downstream
Related
Published
2026-04-09T19:13:13.529Z
Modified
2026-05-18T05:58:37.449476039Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Apache Tomcat: Occasionally open redirect
Details

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100. Other, unsupported versions may also be affected

Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

Database specific
{
    "cna_assigner": "apache",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25854.json",
    "cwe_ids": [
        "CWE-601"
    ],
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "11.0.0-M1"
                },
                {
                    "last_affected": "11.0.18"
                },
                {
                    "introduced": "10.1.0-M1"
                },
                {
                    "last_affected": "10.1.52"
                },
                {
                    "introduced": "9.0.0.M23"
                },
                {
                    "last_affected": "9.0.115"
                },
                {
                    "introduced": "8.5.30"
                },
                {
                    "last_affected": "8.5.100"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "11.0.0-M1"
                },
                {
                    "fixed": "11.0.18"
                },
                {
                    "introduced": "10.1.0-M1"
                },
                {
                    "fixed": "10.1.52"
                },
                {
                    "introduced": "9.0.0.M23"
                },
                {
                    "fixed": "9.0.115"
                },
                {
                    "introduced": "8.5.30"
                },
                {
                    "fixed": "8.5.100"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/apache/tomcat

Affected ranges

Type
GIT
Repo
https://github.com/apache/tomcat
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Last affected
Last affected
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "9.0.0-milestone23"
        },
        {
            "last_affected": "9.0.0-milestone24"
        },
        {
            "last_affected": "9.0.0-milestone25"
        },
        {
            "last_affected": "9.0.0-milestone26"
        },
        {
            "last_affected": "9.0.0-milestone27"
        }
    ],
    "source": "CPE_FIELD",
    "cpe": [
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone23:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone24:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone25:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone26:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone27:*:*:*:*:*:*"
    ]
}

Affected versions

9.*
9.0.0-M23
9.0.0-M24
9.0.0-M25
9.0.0-M26
9.0.0-M27

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-25854.json"