Executive brief
Apache Tomcat is a widely used web server for hosting Java applications. A vulnerability exists where an attacker can send a specially crafted web request that causes malicious commands to be hidden within the server's log files. If an administrator views these logs in a terminal that supports special formatting codes (ANSI sequences), the attacker could potentially manipulate the administrator's console or clipboard to trick them into executing unauthorized commands.
Technical details
Apache Tomcat fails to properly neutralize ANSI escape sequences before writing them to log files. An attacker can trigger this by sending a specially crafted URL containing these sequences, which Tomcat then logs. If the server is running in a console (primarily on Windows) that interprets ANSI sequences, an administrator viewing the logs could be subjected to terminal manipulation or clipboard hijacking. This is classified as CWE-150 (Improper Neutralization of Escape, Meta, or Control Sequences). While the primary risk is identified for Windows environments, other operating systems using ANSI-compliant terminals may also be affected. Patches are available in versions 11.0.11, 10.1.45, and 9.0.109.
Affected products
- Apache Tomcat 11.0.0-M1 through 11.0.10, 10.1.0-M1 through 10.1.44, 9.0.40 through 9.0.108, 8.5.60 through 8.5.100
Timeline
- 2025-10-27: disclosed
- 2025-10-27: advisory