CVE-2025-55752

CVSS 7.5 · HIGH
1 public PoC
Proof-of-concept code linked in references
EPSS p51
Higher than 51% of all CVEs — moderate exploitation risk.
Patch available
Vendor advisory or patch linked

Published 10/27/2025 · updated 5/12/2026 · CWE-23

Share
Get asset-aware triage

Summary

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.

CVSS 7.5HIGH

7.5 / 10
  • AV: Network
  • AC: High complexity
  • PR: Low privileges
  • UI: No user interaction
  • S: Scope unchanged
  • C: Confidentiality: High
  • I: Integrity: High
  • A: Availability: High

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS exploitation probability

0.3%

Percentile p51 Higher than 51% of all CVEs — moderate exploitation risk.

Affected products

1 vendor/product entries
  • Apache Tomcat≥ 8.5.6 and ≤ 8.5.100
Do you run any of these? Sign in to match this CVE against your SBOM and asset inventory automatically.

Timeline

  1. Oct 27, 2025 · Disclosed / published in NVD
  2. May 12, 2026 · Intel last updated

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 53 days ago
  • CVE.org· no data
  • FIRST EPSS· 53 days ago
  • CISA KEV· no data
  • OSV· 53 days ago

References

Unlock the full report

See how CVE-2025-55752 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.