---
title: "CVE-2025-55752\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-55752?format=md
keywords: index, follow
---

# CVE-2025-55752

Publication date 27 October 2025

Last updated 19 March 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2025-55752?format=md#impact-score)

Toggle side navigation

## Description

Relative Path Traversal vulnerability in Apache Tomcat.
The fix for bug 60013 introduced a regression where the rewritten URL
was normalized before it was decoded. This introduced the possibility
that, for rewrite rules that rewrite query parameters to the URL, an
attacker could manipulate the request URI to bypass security
constraints including the protection for /WEB-INF/ and /META-INF/. If PUT
requests were also enabled then malicious files could be uploaded leading
to remote code execution. PUT requests are normally limited to trusted
users and it is considered unlikely that PUT requests would be enabled in
conjunction with a rewrite that manipulated the URI.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from
10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may
also be affected.
Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or
later or 9.0.109 or later, which fix the issue.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| tomcat6 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| tomcat7 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| tomcat10 | 26.04 LTS resolute | Vulnerable |
| 25.10 questing | Ignored end of life, was needed |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Vulnerable |
| 22.04 LTS jammy | Not in release |
| tomcat11 | 26.04 LTS resolute | Not affected |
| 25.10 questing | Ignored end of life, was needed |
| 25.04 plucky | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| tomcat8 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Vulnerable |
| 14.04 LTS trusty | Not in release |
| tomcat9 | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Vulnerable |
| 20.04 LTS focal | Vulnerable |
| 18.04 LTS bionic | Vulnerable |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55752)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-55752)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-55752)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-55752)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-55752>
* <https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog>
* <https://github.com/apache/tomcat/commit/fec06c610ed7466b401e29cc567a58aee5ed826a (11.0.11)>
* <https://github.com/apache/tomcat/commit/130d36d8492ef9e4eb22952c17c92423cb35fd06 (10.1.45)>
* <https://github.com/apache/tomcat/commit/b5042622b8b78340ae65403c55dcb9c7416924df (9.0.109)>
