Description
Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule.







This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.



The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected.



Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121 which fix the issue.
Published: 2026-08-25
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Access Control Bypass
Action: Immediate Patch
AI Analysis

Impact

Off-by-one error in the [N] flag of the RewriteValve causes rewrite processing to restart at the second rule instead of the first. This behavior can allow a request to bypass configured access‑control checks, potentially exposing protected resources. The flaw is an off‑by‑one boundary condition (CWE‑193).

Affected Systems

The flaw affects Apache Tomcat from 11.0.0‑M1 through 11.0.24, from 10.1.0‑M1 through 10.1.57, and from 9.0.0.M1 through 9.0.120. Versions 8.5.0 through 8.5.100, which were already end‑of‑life, also remain vulnerable.

Risk and Exploitability

Because the issue requires manipulating rewrite rules, the attack vector is application‑level via crafted URLs. No publicly available exploit is documented and EPSS < 1%; however, the potential to bypass access control renders the risk moderate to high for any exposed Tomcat instance, with a CVSS score of 7.5. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 26, 2026 at 18:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Tomcat to version 11.0.25, 10.1.58, or 9.0.121 or later.
  • If an upgrade cannot be performed immediately, avoid using the [N] flag in rewrite rules or disable the RewriteValve component until a patch is applied.
  • Review and tighten rewrite rule configurations to prevent accidental rule execution that could expose protected resources.

Generated by OpenCVE AI on August 26, 2026 at 18:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 27 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
References

Wed, 26 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache tomcat
Vendors & Products Apache
Apache tomcat

Tue, 25 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121 which fix the issue.
Title Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control
Weaknesses CWE-193
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-26T15:22:01.843Z

Reserved: 2026-07-23T14:24:12.608Z

Link: CVE-2026-65927

cve-icon Vulnrichment

Updated: 2026-08-26T02:30:38.001Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T22:17:05.433

Modified: 2026-08-27T15:17:08.267

Link: CVE-2026-65927

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-25T21:53:05Z

Links: CVE-2026-65927 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T18:15:08Z

Weaknesses