Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2025-31651 — Original CVE-2025-31651 disclosure with proof-of-concept exploit for Apache Tomcat rewrite rule bypass. Includes technical analysis, reproduction steps, and vendor response timeline. | Kitploit
Tools/GitHubGitHub/gregk4sec/cve-2025-31651
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingMisconfiguration
GitHubgregk4sec/cve-2025-31651

cve-2025-31651

Original CVE-2025-31651 disclosure with proof-of-concept exploit for Apache Tomcat rewrite rule bypass. Includes technical analysis, reproduction steps, and vendor response timeline.

View Repository
86 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Type: CVE Discoverer: gregk4sec Research: Original Status: Public

CVE-2025-36701 — Apache Tomcat - Rewrite rule bypass

Discoverer: gregk4sec (https://github.com/gregk4sec/cve)
Discovery Date: 2025-02-28
Affected Vendor: Apache
Affected Product: Tomcat 9.0.x / 10.1.x / 11.0.x
Severity: Critical / High
CWE: CWE-116
Status: Under Review / Fixed / Public ✅ / Private


Summary

For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed.


Technical Analysis

See: analysis.md


Reproduction Steps

  1. Environment setup
  2. Trigger conditions
  3. Expected vs actual behavior
  4. Screenshots (optional)

Proof of Concept (PoC)

PoC files are located in:

./poc/

Note: Some PoC content may be redacted or published later depending on disclosure requirements.


Disclosure Timeline

See: timeline.md


Vendor Response

See: ./vendor-response/


References

  • CVE Entry: https://nvd.nist.gov/vuln/detail/cve-2025-31651
  • Vendor Advisory: https://lists.apache.org/[email protected]:2025-4
  • Security Bulletin:
  • Related Research:

Attribution

This vulnerability is an original discovery by gregk4sec (https://github.com/gregk4sec/cve).
Repository: https://github.com/gregk4sec/cve

Download Tool