CVE-2025-31651 is an improper neutralization flaw in Apache Tomcat rewrite-rule processing. Under a subset of unlikely rewrite-rule configurations, a specially crafted request can bypass certain rewrite rules. Where the bypassed rules enforce security constraints, the request can evade those constraints. Affected releases are Tomcat 11.0.0-M1 through 11.0.5, 10.1.0-M1 through 10.1.39, and 9.0.0.M1 through 9.0.102. Tomcat 8.5.0 through 8.5.100, which was end-of-life when the CVE was created, is also known to be affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is documentation-only (3 files: README.md, CVE-2025-31651.md, LICENSE) describing a proof-of-concept for CVE-2025-31651 affecting Apache Tomcat 11.0.4 when the Rewrite Valve is enabled. The core issue is a rewrite-rule substitution weakness involving encoded characters (specifically an encoded question mark, %3F) that can allow a specially crafted request to bypass certain rewrite rules. The PoC scenario shows a configuration where direct access to /order-files/* is blocked by rewriting to /403.jsp, while /orders/* is rewritten into /order-files/$1/detail.xml. By appending %3F to a request under /orders/ (e.g., /sec/orders/housekeeper.jsp%3f or /sec/orders/secret.yml%3f), an attacker can cause the server to return 200 and access resources that should be blocked or non-existent under normal routing. Impact includes rewrite-based access control bypass, potential bypass of security constraints if they rely on those rewrite rules, unintended JSP execution, and disclosure of sensitive configuration/data files. No exploit automation code, scanner, or framework module is included—only reproduction steps and example URLs.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific vulnerability addressed by the referenced TuxCare/Rocky Linux 9.6 security advisory; the supplied content provides no technical vulnerability description.
A vulnerability referenced by an Alma Linux 9.6 local security-check plugin. The plugin rates it as critical and states that exploits are available.
A critical network-accessible vulnerability tracked as CVE-2025-31651. The provided CVSS v3 vector indicates low-complexity, unauthenticated remote exploitation with no user interaction and potential for high impact to confidentiality, integrity, and availability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.