Vulnerability Database

296,137

Total vulnerabilities in the database

CVE-2025-55668

Session Fixation vulnerability in Apache Tomcat via rewrite valve.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected.

Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

CVSS v3:

  • Severity: Unknown
  • Score:
  • AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Software From Fixed in
Maven icon org.apache.tomcat / tomcat-catalina 11.0.0-M1 11.0.8
Maven icon org.apache.tomcat / tomcat-catalina 10.1.0-M1 10.1.42
Maven icon org.apache.tomcat / tomcat-catalina 9.0.0.M1 9.0.106
apache / tomcat 9.0.0-milestone1 9.0.0-milestone1.x
apache / tomcat 9.0.0-milestone10 9.0.0-milestone10.x
apache / tomcat 9.0.0-milestone11 9.0.0-milestone11.x
apache / tomcat 9.0.0-milestone12 9.0.0-milestone12.x
apache / tomcat 9.0.0-milestone13 9.0.0-milestone13.x
apache / tomcat 9.0.0-milestone14 9.0.0-milestone14.x
apache / tomcat 9.0.0-milestone15 9.0.0-milestone15.x
apache / tomcat 9.0.0-milestone16 9.0.0-milestone16.x
apache / tomcat 9.0.0-milestone17 9.0.0-milestone17.x
apache / tomcat 9.0.0-milestone18 9.0.0-milestone18.x
apache / tomcat 9.0.0-milestone19 9.0.0-milestone19.x
apache / tomcat 9.0.0-milestone2 9.0.0-milestone2.x
apache / tomcat 9.0.0-milestone20 9.0.0-milestone20.x
apache / tomcat 9.0.0-milestone21 9.0.0-milestone21.x
apache / tomcat 9.0.0-milestone22 9.0.0-milestone22.x
apache / tomcat 9.0.0-milestone23 9.0.0-milestone23.x
apache / tomcat 9.0.0-milestone24 9.0.0-milestone24.x
apache / tomcat 9.0.0-milestone25 9.0.0-milestone25.x
apache / tomcat 10.0.0 10.1.42
apache / tomcat 11.0.0 11.0.8
apache / tomcat 9.0.0-milestone9 9.0.0-milestone9.x
apache / tomcat 9.0.0-milestone26 9.0.0-milestone26.x
apache / tomcat 9.0.0-milestone27 9.0.0-milestone27.x
apache / tomcat 9.0.0-milestone3 9.0.0-milestone3.x
apache / tomcat 9.0.0-milestone4 9.0.0-milestone4.x
apache / tomcat 9.0.0-milestone5 9.0.0-milestone5.x
apache / tomcat 9.0.0-milestone6 9.0.0-milestone6.x
apache / tomcat 9.0.0-milestone7 9.0.0-milestone7.x
apache / tomcat 9.0.0-milestone8 9.0.0-milestone8.x
apache / tomcat 9.0.1 9.0.106