[CLSA-2026:1786542969] Fix CVE(s): CVE-2025-31651
Type:
security
Severity:
Critical
Release date:
2026-08-12 13:56:20 UTC
Description:
* SECURITY UPDATE: rewrite rule bypass with encoded characters - debian/patches/CVE-2025-31651.patch: encode literal '%', ';' and '?' in the URL before the rewrite rules are evaluated and treat '%' as safe when re-encoding afterwards in java/org/apache/catalina/valves/rewrite/RewriteValve.java, stop truncating the decoded URI at the first ';' when a rewritten request is re-dispatched in java/org/apache/catalina/connector/CoyoteAdapter.java, add tests to test/org/apache/catalina/valves/rewrite/TestRewriteValve.java - CVE-2025-31651
CVEs fixed:
Updated packages:
  • libservlet3.1-java_8.0.32-1ubuntu1.13+tuxcare.els4_all.deb
    sha:864649d842b310dc27ce54f194168fbf4e70f220
  • libservlet3.1-java-doc_8.0.32-1ubuntu1.13+tuxcare.els4_all.deb
    sha:ea1176ab72be889091ee5ba5f98d1267de005896
  • libtomcat8-java_8.0.32-1ubuntu1.13+tuxcare.els4_all.deb
    sha:bbc9c8934fb9b178bc6469c4306feface67f7667
  • tomcat8_8.0.32-1ubuntu1.13+tuxcare.els4_all.deb
    sha:cc3ecce4783311adf2bfc174956d6405db34f7e4
  • tomcat8-admin_8.0.32-1ubuntu1.13+tuxcare.els4_all.deb
    sha:44dbef45f8dd47c3890a1652f2c8d2331e9e1c00
  • tomcat8-common_8.0.32-1ubuntu1.13+tuxcare.els4_all.deb
    sha:8a13a3a234a2d6f8972c3bd08fc85875390198d5
  • tomcat8-docs_8.0.32-1ubuntu1.13+tuxcare.els4_all.deb
    sha:344db954e32ee4e336152471cd7e886d44674934
  • tomcat8-examples_8.0.32-1ubuntu1.13+tuxcare.els4_all.deb
    sha:e050578481c8e2b554eb8ee1541e399db7cfef51
  • tomcat8-user_8.0.32-1ubuntu1.13+tuxcare.els4_all.deb
    sha:a1cc4bb5950b9ee7731321442ecb94cd44c03969
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.