CVE-2026-25854 PUBLISHED

Apache Tomcat: Occasionally open redirect

Assigner: apache
Reserved: 06.02.2026 Published: 09.04.2026 Updated: 09.04.2026

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100. Other, unsupported versions may also be affected

Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

Product Status

Vendor Apache Software Foundation
Product Apache Tomcat
Versions Default: unaffected
  • affected from 11.0.0-M1 to 11.0.18 (incl.)
  • affected from 10.1.0-M1 to 10.1.52 (incl.)
  • affected from 9.0.0.M23 to 9.0.115 (incl.)
  • affected from 8.5.30 to 8.5.100 (incl.)
  • unaffected from 0 to 7.0.109 (incl.)

Credits

  • gregk4sec (https://github.com/gregk4sec) finder

References

Problem Types

  • CWE-601 URL Redirection to Untrusted Site ('Open Redirect') CWE