Loading...
Skip to main content

CVE-2025-55752

HIGH

Apache Tomcat Vulnerable to Relative Path Traversal

Published October 27, 2025Updated May 13, 2026Source: osv

Summary

The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.

Remediation

Upgrade to the fixed version using your package manager.

Maven
Update org.apache.tomcat:tomcat to 9.0.109 or later
<!-- Update pom.xml dependency version to 9.0.109 for org.apache.tomcat:tomcat -->
Maven
Update org.apache.tomcat.embed:tomcat-embed-core to 11.0.11 or later
<!-- Update pom.xml dependency version to 11.0.11 for org.apache.tomcat.embed:tomcat-embed-core -->
Maven
Update org.apache.tomcat:tomcat to 11.0.11 or later
<!-- Update pom.xml dependency version to 11.0.11 for org.apache.tomcat:tomcat -->
Maven
Update org.apache.tomcat.embed:tomcat-embed-core to 9.0.109 or later
<!-- Update pom.xml dependency version to 9.0.109 for org.apache.tomcat.embed:tomcat-embed-core -->
Maven
Update org.apache.tomcat:tomcat to 10.1.45 or later
<!-- Update pom.xml dependency version to 10.1.45 for org.apache.tomcat:tomcat -->
Maven
Update org.apache.tomcat:tomcat-catalina to 10.1.45 or later
<!-- Update pom.xml dependency version to 10.1.45 for org.apache.tomcat:tomcat-catalina -->
Maven
Update org.apache.tomcat.embed:tomcat-embed-core to 10.1.45 or later
<!-- Update pom.xml dependency version to 10.1.45 for org.apache.tomcat.embed:tomcat-embed-core -->
Maven
Update org.apache.tomcat:tomcat-catalina to 11.0.11 or later
<!-- Update pom.xml dependency version to 11.0.11 for org.apache.tomcat:tomcat-catalina -->
Maven
Update org.apache.tomcat:tomcat-catalina to 9.0.109 or later
<!-- Update pom.xml dependency version to 9.0.109 for org.apache.tomcat:tomcat-catalina -->

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (12)

PackageEcosystemAffectedFixed In
org.apache.tomcat:tomcat
maven
9.0.0.M1, 9.0.0.M10, 9.0.0.M11, 9.0.0.M13 (+104 more)9.0.109
org.apache.tomcat.embed:tomcat-embed-core
maven
11.0.0, 11.0.0-M1, 11.0.0-M10, 11.0.0-M11 (+30 more)11.0.11
org.apache.tomcat:tomcat
maven
11.0.0, 11.0.0-M1, 11.0.0-M10, 11.0.0-M11 (+30 more)11.0.11
org.apache.tomcat.embed:tomcat-embed-core
maven
8.5.100, 8.5.11, 8.5.12, 8.5.13 (+76 more)Range-based data available
org.apache.tomcat.embed:tomcat-embed-core
maven
9.0.0.M1, 9.0.0.M10, 9.0.0.M11, 9.0.0.M13 (+104 more)9.0.109
org.apache.tomcat:tomcat
maven
8.5.100, 8.5.11, 8.5.12, 8.5.13 (+76 more)Range-based data available
org.apache.tomcat:tomcat
maven
10.1.0, 10.1.0-M1, 10.1.0-M10, 10.1.0-M11 (+48 more)10.1.45
org.apache.tomcat:tomcat-catalina
maven
10.1.0, 10.1.0-M1, 10.1.0-M10, 10.1.0-M11 (+48 more)10.1.45
org.apache.tomcat:tomcat-catalina
maven
8.5.100, 8.5.11, 8.5.12, 8.5.13 (+76 more)Range-based data available
org.apache.tomcat.embed:tomcat-embed-core
maven
10.1.0, 10.1.0-M1, 10.1.0-M10, 10.1.0-M11 (+48 more)10.1.45
org.apache.tomcat:tomcat-catalina
maven
11.0.0, 11.0.0-M1, 11.0.0-M10, 11.0.0-M11 (+30 more)11.0.11
org.apache.tomcat:tomcat-catalina
maven
9.0.0.M1, 9.0.0.M10, 9.0.0.M11, 9.0.0.M13 (+104 more)9.0.109

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 7.5 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Frequently Asked Questions

What is CVE-2025-55752?
Apache Tomcat Vulnerable to Relative Path Traversal This vulnerability has been assigned a severity rating of HIGH (CVSS score: 7.5/10).
How do I check if my project is affected by CVE-2025-55752?
CVE-2025-55752 affects org.apache.tomcat:tomcat, org.apache.tomcat.embed:tomcat-embed-core and org.apache.tomcat:tomcat-catalina. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2025-55752 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
7.5

High exploitability or significant impact. Prioritize remediation within days.

Also Known As

GHSA-wmwf-9ccg-fff5
BIT-tomcat-2025-55752

Related CVEs

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies