CVE-2025-46701

high
Published 2026-05-19 · Modified 2026-02-04
CVSS v3
CVSS v2
VIR risk
8.0

Description

Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-46701

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-46701.html

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:18916

OS impact

OSVersionStatusFixed in
arch archaffected
redhat rhel9fixed
suse slesaffected
debian debianbookwormfixed10.1.52-1~deb12u1
debian debianforkyfixed10.1.46-1
debian debiansidfixed10.1.46-1
debian debiantrixiefixed10.1.52-1~deb13u1
debian debianbullseyefixed9.0.107-0+deb11u1

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.tomcat:tomcat-catalina>=9.0.0.M1,<9.0.1059.0.105
java Mavenorg.apache.tomcat:tomcat-catalina>=10.1.0-M1,<10.1.4110.1.41
java Mavenorg.apache.tomcat:tomcat-catalina>=11.0.0-M1,<11.0.711.0.7
java Mavenorg.apache.tomcat.embed:tomcat-embed-core>=9.0.0.M1,<9.0.1059.0.105
java Mavenorg.apache.tomcat.embed:tomcat-embed-core>=10.1.0-M1,<10.1.4110.1.41
java Mavenorg.apache.tomcat.embed:tomcat-embed-core>=11.0.0-M1,<11.0.711.0.7
java Mavenorg.apache.tomcat:tomcat-catalina>=8.5.0,<=8.5.100
java Mavenorg.apache.tomcat.embed:tomcat-embed-core>=8.5.0,<=8.5.100

References

Verify integrity in audit chain (admin only). AS-IS.