{"schema_version":"1.7.5","id":"GHSA-vfww-5hm6-hx2j","published":"2025-10-27T18:31:13Z","modified":"2026-05-13T16:35:23.699719Z","aliases":["BIT-tomcat-2025-55754","CVE-2025-55754"],"related":["CGA-wwph-fxq5-rj2m"],"summary":"Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences","details":"Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108.\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected.\nUsers are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.","affected":[{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0-M1"},{"fixed":"11.0.11"}]}],"versions":["11.0.0","11.0.0-M1","11.0.0-M10","11.0.0-M11","11.0.0-M12","11.0.0-M13","11.0.0-M14","11.0.0-M15","11.0.0-M16","11.0.0-M17","11.0.0-M18","11.0.0-M19","11.0.0-M20","11.0.0-M21","11.0.0-M22","11.0.0-M24","11.0.0-M25","11.0.0-M26","11.0.0-M3","11.0.0-M4","11.0.0-M5","11.0.0-M6","11.0.0-M7","11.0.0-M9","11.0.1","11.0.10","11.0.2","11.0.3","11.0.4","11.0.5","11.0.6","11.0.7","11.0.8","11.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-vfww-5hm6-hx2j/GHSA-vfww-5hm6-hx2j.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.0-M1"},{"fixed":"10.1.45"}]}],"versions":["10.1.0","10.1.0-M1","10.1.0-M10","10.1.0-M11","10.1.0-M12","10.1.0-M14","10.1.0-M15","10.1.0-M16","10.1.0-M17","10.1.0-M2","10.1.0-M4","10.1.0-M5","10.1.0-M6","10.1.0-M7","10.1.0-M8","10.1.1","10.1.10","10.1.11","10.1.12","10.1.13","10.1.14","10.1.15","10.1.16","10.1.17","10.1.18","10.1.19","10.1.2","10.1.20","10.1.23","10.1.24","10.1.25","10.1.26","10.1.28","10.1.29","10.1.30","10.1.31","10.1.33","10.1.34","10.1.35","10.1.36","10.1.39","10.1.4","10.1.40","10.1.41","10.1.42","10.1.43","10.1.44","10.1.5","10.1.6","10.1.7","10.1.8","10.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-vfww-5hm6-hx2j/GHSA-vfww-5hm6-hx2j.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.40"},{"fixed":"9.0.109"}]}],"versions":["9.0.100","9.0.102","9.0.104","9.0.105","9.0.106","9.0.107","9.0.108","9.0.40","9.0.41","9.0.43","9.0.44","9.0.45","9.0.46","9.0.48","9.0.50","9.0.52","9.0.53","9.0.54","9.0.55","9.0.56","9.0.58","9.0.59","9.0.60","9.0.62","9.0.63","9.0.64","9.0.65","9.0.67","9.0.68","9.0.69","9.0.70","9.0.71","9.0.72","9.0.73","9.0.74","9.0.75","9.0.76","9.0.78","9.0.79","9.0.80","9.0.81","9.0.82","9.0.83","9.0.84","9.0.85","9.0.86","9.0.87","9.0.88","9.0.89","9.0.90","9.0.91","9.0.93","9.0.94","9.0.95","9.0.96","9.0.97","9.0.98","9.0.99"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-vfww-5hm6-hx2j/GHSA-vfww-5hm6-hx2j.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.5.60"},{"last_affected":"8.5.100"}]}],"versions":["8.5.100","8.5.60","8.5.61","8.5.63","8.5.64","8.5.65","8.5.66","8.5.68","8.5.69","8.5.70","8.5.71","8.5.72","8.5.73","8.5.75","8.5.76","8.5.77","8.5.78","8.5.79","8.5.81","8.5.82","8.5.83","8.5.84","8.5.85","8.5.86","8.5.87","8.5.88","8.5.89","8.5.90","8.5.91","8.5.92","8.5.93","8.5.94","8.5.95","8.5.96","8.5.97","8.5.98","8.5.99"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-vfww-5hm6-hx2j/GHSA-vfww-5hm6-hx2j.json"}},{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0-M1"},{"fixed":"11.0.11"}]}],"versions":["11.0.0","11.0.0-M1","11.0.0-M10","11.0.0-M11","11.0.0-M12","11.0.0-M13","11.0.0-M14","11.0.0-M15","11.0.0-M16","11.0.0-M17","11.0.0-M18","11.0.0-M19","11.0.0-M20","11.0.0-M21","11.0.0-M22","11.0.0-M24","11.0.0-M25","11.0.0-M26","11.0.0-M3","11.0.0-M4","11.0.0-M5","11.0.0-M6","11.0.0-M7","11.0.0-M9","11.0.1","11.0.10","11.0.2","11.0.3","11.0.4","11.0.5","11.0.6","11.0.7","11.0.8","11.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-vfww-5hm6-hx2j/GHSA-vfww-5hm6-hx2j.json"}},{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.0-M1"},{"fixed":"10.1.45"}]}],"versions":["10.1.0","10.1.0-M1","10.1.0-M10","10.1.0-M11","10.1.0-M12","10.1.0-M14","10.1.0-M15","10.1.0-M16","10.1.0-M17","10.1.0-M2","10.1.0-M4","10.1.0-M5","10.1.0-M6","10.1.0-M7","10.1.0-M8","10.1.1","10.1.10","10.1.11","10.1.12","10.1.13","10.1.14","10.1.15","10.1.16","10.1.17","10.1.18","10.1.19","10.1.2","10.1.20","10.1.23","10.1.24","10.1.25","10.1.26","10.1.28","10.1.29","10.1.30","10.1.31","10.1.33","10.1.34","10.1.35","10.1.36","10.1.39","10.1.4","10.1.40","10.1.41","10.1.42","10.1.43","10.1.44","10.1.5","10.1.6","10.1.7","10.1.8","10.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-vfww-5hm6-hx2j/GHSA-vfww-5hm6-hx2j.json"}},{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.40"},{"fixed":"9.0.109"}]}],"versions":["9.0.100","9.0.102","9.0.104","9.0.105","9.0.106","9.0.107","9.0.108","9.0.40","9.0.41","9.0.43","9.0.44","9.0.45","9.0.46","9.0.48","9.0.50","9.0.52","9.0.53","9.0.54","9.0.55","9.0.56","9.0.58","9.0.59","9.0.60","9.0.62","9.0.63","9.0.64","9.0.65","9.0.67","9.0.68","9.0.69","9.0.70","9.0.71","9.0.72","9.0.73","9.0.74","9.0.75","9.0.76","9.0.78","9.0.79","9.0.80","9.0.81","9.0.82","9.0.83","9.0.84","9.0.85","9.0.86","9.0.87","9.0.88","9.0.89","9.0.90","9.0.91","9.0.93","9.0.94","9.0.95","9.0.96","9.0.97","9.0.98","9.0.99"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-vfww-5hm6-hx2j/GHSA-vfww-5hm6-hx2j.json"}},{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.5.60"},{"last_affected":"8.5.100"}]}],"versions":["8.5.100","8.5.60","8.5.61","8.5.63","8.5.64","8.5.65","8.5.66","8.5.68","8.5.69","8.5.70","8.5.71","8.5.72","8.5.73","8.5.75","8.5.76","8.5.77","8.5.78","8.5.79","8.5.81","8.5.82","8.5.83","8.5.84","8.5.85","8.5.86","8.5.87","8.5.88","8.5.89","8.5.90","8.5.91","8.5.92","8.5.93","8.5.94","8.5.95","8.5.96","8.5.97","8.5.98","8.5.99"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-vfww-5hm6-hx2j/GHSA-vfww-5hm6-hx2j.json"}},{"package":{"name":"org.apache.tomcat:tomcat-catalina","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-catalina"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0-M1"},{"fixed":"11.0.11"}]}],"versions":["11.0.0","11.0.0-M1","11.0.0-M10","11.0.0-M11","11.0.0-M12","11.0.0-M13","11.0.0-M14","11.0.0-M15","11.0.0-M16","11.0.0-M17","11.0.0-M18","11.0.0-M19","11.0.0-M20","11.0.0-M21","11.0.0-M22","11.0.0-M24","11.0.0-M25","11.0.0-M26","11.0.0-M3","11.0.0-M4","11.0.0-M5","11.0.0-M6","11.0.0-M7","11.0.0-M9","11.0.1","11.0.10","11.0.2","11.0.3","11.0.4","11.0.5","11.0.6","11.0.7","11.0.8","11.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-vfww-5hm6-hx2j/GHSA-vfww-5hm6-hx2j.json"}},{"package":{"name":"org.apache.tomcat:tomcat-catalina","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-catalina"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.0-M1"},{"fixed":"10.1.45"}]}],"versions":["10.1.0","10.1.0-M1","10.1.0-M10","10.1.0-M11","10.1.0-M12","10.1.0-M14","10.1.0-M15","10.1.0-M16","10.1.0-M17","10.1.0-M2","10.1.0-M4","10.1.0-M5","10.1.0-M6","10.1.0-M7","10.1.0-M8","10.1.1","10.1.10","10.1.11","10.1.12","10.1.13","10.1.14","10.1.15","10.1.16","10.1.17","10.1.18","10.1.19","10.1.2","10.1.20","10.1.23","10.1.24","10.1.25","10.1.26","10.1.28","10.1.29","10.1.30","10.1.31","10.1.33","10.1.34","10.1.35","10.1.36","10.1.39","10.1.4","10.1.40","10.1.41","10.1.42","10.1.43","10.1.44","10.1.5","10.1.6","10.1.7","10.1.8","10.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-vfww-5hm6-hx2j/GHSA-vfww-5hm6-hx2j.json"}},{"package":{"name":"org.apache.tomcat:tomcat-catalina","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-catalina"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.40"},{"fixed":"9.0.109"}]}],"versions":["9.0.100","9.0.102","9.0.104","9.0.105","9.0.106","9.0.107","9.0.108","9.0.40","9.0.41","9.0.43","9.0.44","9.0.45","9.0.46","9.0.48","9.0.50","9.0.52","9.0.53","9.0.54","9.0.55","9.0.56","9.0.58","9.0.59","9.0.60","9.0.62","9.0.63","9.0.64","9.0.65","9.0.67","9.0.68","9.0.69","9.0.70","9.0.71","9.0.72","9.0.73","9.0.74","9.0.75","9.0.76","9.0.78","9.0.79","9.0.80","9.0.81","9.0.82","9.0.83","9.0.84","9.0.85","9.0.86","9.0.87","9.0.88","9.0.89","9.0.90","9.0.91","9.0.93","9.0.94","9.0.95","9.0.96","9.0.97","9.0.98","9.0.99"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-vfww-5hm6-hx2j/GHSA-vfww-5hm6-hx2j.json"}},{"package":{"name":"org.apache.tomcat:tomcat-catalina","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-catalina"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.5.60"},{"last_affected":"8.5.100"}]}],"versions":["8.5.100","8.5.60","8.5.61","8.5.63","8.5.64","8.5.65","8.5.66","8.5.68","8.5.69","8.5.70","8.5.71","8.5.72","8.5.73","8.5.75","8.5.76","8.5.77","8.5.78","8.5.79","8.5.81","8.5.82","8.5.83","8.5.84","8.5.85","8.5.86","8.5.87","8.5.88","8.5.89","8.5.90","8.5.91","8.5.92","8.5.93","8.5.94","8.5.95","8.5.96","8.5.97","8.5.98","8.5.99"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-vfww-5hm6-hx2j/GHSA-vfww-5hm6-hx2j.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55754"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/138d7f5cfaae683078948303333c080e6faa75d2"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/5a3db092982c0c58d4855304167ee757fe5e79bb"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/a03cabf3a36a42d27d8d997ed31f034f50ba6cd5"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-032379.html"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"https://lists.apache.org/thread/j7w54hqbkfcn0xb9xy0wnx8w5nymcbqd"},{"type":"WEB","url":"https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.45"},{"type":"WEB","url":"https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.11"},{"type":"WEB","url":"https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.109"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/10/27/5"}],"database_specific":{"cwe_ids":["CWE-150"],"github_reviewed":true,"github_reviewed_at":"2025-10-28T17:57:42Z","nvd_published_at":"2025-10-27T18:15:42Z","severity":"LOW"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}