Junglewise Threat Intelligence

CVE-2026-65927: Apache Tomcat off-by-one error in RewriteValve [N] flag

CVE-2026-65927 · Severity: high · CVSS 7.5 · Published 2026-08-25

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat's rewrite valve component contains a logic error that causes URL rewrite rules with the [N] flag (restart processing) to begin at the second rule instead of the first. This can allow attackers to bypass security rules and access control policies that would have been applied if rule processing had correctly restarted from the beginning.

Technical details

An off-by-one error in the RewriteValve implementation causes the [N] flag to restart rewrite rule processing at index 1 (the second rule) rather than index 0 (the first rule). This is a logic bug in the rewrite engine that processes URL rewrite rules. The vulnerability is network-accessible as it affects URL routing decisions on all HTTP requests. An attacker can craft requests that exploit the missed first rule to bypass access control policies or bypass security rules that depend on proper rule ordering. Patches are available in Tomcat 11.0.25, 10.1.58, and 9.0.121.

Affected products

  • Apache Tomcat 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0-M1 through 9.0.120, 8.5.0 through 8.5.100

Timeline

  • 2026-08-25: disclosed: Vulnerability publicly disclosed
  • patched: Fixed in Tomcat 11.0.25, 10.1.58, and 9.0.121

References

Related threats