
Original CVE-2025-31651 disclosure with proof-of-concept exploit for Apache Tomcat rewrite rule bypass. Includes technical analysis, reproduction steps, and vendor response timeline.
Discoverer: gregk4sec (https://github.com/gregk4sec/cve)
Discovery Date: 2025-02-28
Affected Vendor: Apache
Affected Product: Tomcat 9.0.x / 10.1.x / 11.0.x
Severity: Critical / High
CWE: CWE-116
Status: Under Review / Fixed / Public ✅ / Private
For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed.
See: analysis.md
PoC files are located in:
./poc/
Note: Some PoC content may be redacted or published later depending on disclosure requirements.
See: timeline.md
See: ./vendor-response/
This vulnerability is an original discovery by gregk4sec (https://github.com/gregk4sec/cve).
Repository: https://github.com/gregk4sec/cve