Apache Tomcat: Bad ornext processing in RewriteValve
Published Jun 29, 2026
7.3
HIGHCVSS 3.1
EPSS 0.65%
Description
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
Affected products
-
- Version 10.1.0-M1StatusaffectedConstraints<=10.1.55
- Version 11.0.0-M1StatusaffectedConstraints<=11.0.22
- Version 8.5.0StatusaffectedConstraints<=8.5.100
- Version 9.0.0.M1StatusaffectedConstraints<=9.0.118
- Version 0StatusunaffectedConstraints<8.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | unaffected |
|
No data.
Red Hat Hardened Images
tomcat10-main-10.1.56-1.hum1
Fixed · RHSA-2026:29203
Red Hat Hardened Images
tomcat11-main-11.0.23-0.1.hum1
Fixed · RHSA-2026:32960
Red Hat JBoss Web Server 6.2 on RHEL 10
jws6-tomcat-0:10.1.49-15.redhat_00013.1.el10jws
Fixed · RHSA-2026:43401
Red Hat JBoss Web Server 6.2 on RHEL 8
jws6-tomcat-0:10.1.49-15.redhat_00013.1.el8jws
Fixed · RHSA-2026:43401
Red Hat JBoss Web Server 6.2 on RHEL 9
jws6-tomcat-0:10.1.49-15.redhat_00013.1.el9jws
Fixed · RHSA-2026:43401
Red Hat JBoss Web Server 6.2.4
tomcat-catalina
Fixed · RHSA-2026:43402
Red Hat JBoss Web Server 7.0 on RHEL 10
jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws
Fixed · RHSA-2026:49951
Red Hat JBoss Web Server 7.0 on RHEL 8
jws7-tomcat-0:11.0.21-6.redhat_00005.1.el8jws
Fixed · RHSA-2026:49951
Red Hat JBoss Web Server 7.0 on RHEL 9
jws7-tomcat-0:11.0.21-6.redhat_00005.1.el9jws
Fixed · RHSA-2026:49951
Red Hat JBoss Web Server 7.0.1
tomcat-catalina
Fixed · RHSA-2026:49952
Red Hat Enterprise Linux 10
tomcat
Fix deferred
Red Hat Enterprise Linux 10
tomcat9
Fix deferred
Red Hat Enterprise Linux 6
tomcat6
Fix deferred
Red Hat Enterprise Linux 7
tomcat
Fix deferred
Red Hat Enterprise Linux 8
pki-deps:10.6/pki-servlet-engine
Fix deferred
Red Hat Enterprise Linux 8
tomcat
Fix deferred
Red Hat Enterprise Linux 9
pki-servlet-engine
Fix deferred
Red Hat Enterprise Linux 9
tomcat
Fix deferred
Red Hat JBoss Web Server 5
jws5-tomcat
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | tomcat10-main-10.1.56-1.hum1 | Fixed | RHSA-2026:29203 |
| Red Hat Hardened Images | tomcat11-main-11.0.23-0.1.hum1 | Fixed | RHSA-2026:32960 |
| Red Hat JBoss Web Server 6.2 on RHEL 10 | jws6-tomcat-0:10.1.49-15.redhat_00013.1.el10jws | Fixed | RHSA-2026:43401 |
| Red Hat JBoss Web Server 6.2 on RHEL 8 | jws6-tomcat-0:10.1.49-15.redhat_00013.1.el8jws | Fixed | RHSA-2026:43401 |
| Red Hat JBoss Web Server 6.2 on RHEL 9 | jws6-tomcat-0:10.1.49-15.redhat_00013.1.el9jws | Fixed | RHSA-2026:43401 |
| Red Hat JBoss Web Server 6.2.4 | tomcat-catalina | Fixed | RHSA-2026:43402 |
| Red Hat JBoss Web Server 7.0 on RHEL 10 | jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws | Fixed | RHSA-2026:49951 |
| Red Hat JBoss Web Server 7.0 on RHEL 8 | jws7-tomcat-0:11.0.21-6.redhat_00005.1.el8jws | Fixed | RHSA-2026:49951 |
| Red Hat JBoss Web Server 7.0 on RHEL 9 | jws7-tomcat-0:11.0.21-6.redhat_00005.1.el9jws | Fixed | RHSA-2026:49951 |
| Red Hat JBoss Web Server 7.0.1 | tomcat-catalina | Fixed | RHSA-2026:49952 |
| Red Hat Enterprise Linux 10 | tomcat | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | tomcat9 | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | tomcat6 | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | tomcat | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | pki-deps:10.6/pki-servlet-engine | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | tomcat | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | pki-servlet-engine | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | tomcat | Fix deferred | n/a |
| Red Hat JBoss Web Server 5 | jws5-tomcat | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A flaw was found in Apache Tomcat's RewriteValve. When rewrite rules use OR-chained conditions followed by non-OR conditions, the processing logic may not evaluate conditions correctly, potentially allowing unintended rule matches. Exploitation requires the RewriteValve to be enabled with specific OR-chained condition patterns, which is not a default configuration.
Red Hat mitigation
This vulnerability only affects Tomcat deployments that use the RewriteValve with OR-chained rewrite conditions. Deployments that do not use the RewriteValve are not affected. Review rewrite rules for OR-chained conditions and test rule evaluation behavior.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jun 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Jun–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.65% (0.00652) | 49.44th | v5 (v2026.06.15) |
| Jun 30, 2026 | 0.17% (0.00174) | 7.08th | v5 (v2026.06.15) |
References (6)
- http://www.openwall.com/lists/oss-security/2026/06/29/21 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-53404 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2494681 Issue Tracking
- https://lists.apache.org/thread/rdhpghgfskrdmw9hqzjgjrtw538smpmz vendor-advisoryVendor AdvisoryMailing List
- https://nvd.nist.gov/vuln/detail/CVE-2026-53404
- https://www.cve.org/CVERecord?id=CVE-2026-53404
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/29/21 | Third Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2026-53404 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2494681 | Issue Tracking | |
| https://lists.apache.org/thread/rdhpghgfskrdmw9hqzjgjrtw538smpmz | vendor-advisoryVendor AdvisoryMailing List | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-53404 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-53404 |
Change history (0)
No recorded changes yet.