Home

Description

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

PUBLISHED Reserved 2025-08-13 | Published 2025-08-13 | Updated 2025-08-13 | Assigner apache

Problem types

CWE-384 Session Fixation

Product status

Default status
unaffected

11.0.0-M1
affected

10.1.0-M1
affected

9.0.0.M1
affected

8 before 9.0.0.M1
unknown

Credits

Greg K (https://github.com/gregk4sec) finder

References

lists.apache.org/thread/v6bknr96rl7l1qxkl1c03v0qdvbbqs47 vendor-advisory

cve.org (CVE-2025-55668)

nvd.nist.gov (CVE-2025-55668)

Download JSON