CVE-2025-55754: Apache Tomcat: console manipulation via escape sequences in log messages

Published Oct 27, 2025
·
Updated

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.

Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108.

The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.

Affected Software

19 affected componentsFixes available
Apache Tomcat>=11.0.0-M1<=11.0.10, >=10.1.0-M1<=10.1.44, >=9.0.40<=9.0.108, =8.5.60
maven/org.apache.tomcat:tomcat-catalina>=9.0.40<9.0.109
9.0.109
maven/org.apache.tomcat.embed:tomcat-embed-core>=9.0.40<9.0.109
9.0.109
maven/org.apache.tomcat:tomcat>=9.0.40<9.0.109
9.0.109
maven/org.apache.tomcat:tomcat-catalina>=8.5.60<=8.5.100
maven/org.apache.tomcat:tomcat-catalina>=10.1.0-M1<10.1.45
10.1.45
maven/org.apache.tomcat:tomcat-catalina>=11.0.0-M1<11.0.11
11.0.11
maven/org.apache.tomcat.embed:tomcat-embed-core>=8.5.60<=8.5.100
maven/org.apache.tomcat.embed:tomcat-embed-core>=10.1.0-M1<10.1.45
10.1.45
maven/org.apache.tomcat.embed:tomcat-embed-core>=11.0.0-M1<11.0.11
11.0.11
maven/org.apache.tomcat:tomcat>=8.5.60<=8.5.100
maven/org.apache.tomcat:tomcat>=10.1.0-M1<10.1.45
10.1.45
maven/org.apache.tomcat:tomcat>=11.0.0-M1<11.0.11
11.0.11
Apache Tomcat>=8.5.60<=8.5.100
Apache Tomcat>=9.0.40<9.0.109
Apache Tomcat>=10.0.0<10.0.27
Apache Tomcat>=10.1.0<10.1.45
Apache Tomcat>=11.0.0<11.0.11
IBM API Connect V12 OnPrem<=All

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.apache.tomcat:tomcat-catalina to a version that resolves this vulnerability.

    Fixed in 9.0.109
  2. Upgrade

    Upgrade maven/org.apache.tomcat.embed:tomcat-embed-core to a version that resolves this vulnerability.

    Fixed in 9.0.109
  3. Upgrade

    Upgrade maven/org.apache.tomcat:tomcat to a version that resolves this vulnerability.

    Fixed in 9.0.109
  4. Upgrade

    Upgrade maven/org.apache.tomcat:tomcat-catalina to a version that resolves this vulnerability.

    Fixed in 10.1.45
  5. Upgrade

    Upgrade maven/org.apache.tomcat:tomcat-catalina to a version that resolves this vulnerability.

    Fixed in 11.0.11
  6. Upgrade

    Upgrade maven/org.apache.tomcat.embed:tomcat-embed-core to a version that resolves this vulnerability.

    Fixed in 10.1.45
  7. Upgrade

    Upgrade maven/org.apache.tomcat.embed:tomcat-embed-core to a version that resolves this vulnerability.

    Fixed in 11.0.11
  8. Upgrade

    Upgrade maven/org.apache.tomcat:tomcat to a version that resolves this vulnerability.

    Fixed in 10.1.45
  9. Upgrade

    Upgrade maven/org.apache.tomcat:tomcat to a version that resolves this vulnerability.

    Fixed in 11.0.11
  10. Upgrade

    Upgrade Apache Tomcat to a version that resolves this vulnerability.

    Fixed in 11.0.11
  11. Upgrade

    Upgrade Apache Tomcat to a version that resolves this vulnerability.

    Fixed in 10.1.45
  12. Upgrade

    Upgrade Apache Tomcat to a version that resolves this vulnerability.

    Fixed in 9.0.109
  13. Compensating control

    If Tomcat is running on Windows in a console that supports ANSI escape sequences, consider disabling/restricting ANSI escape sequence support in that console environment to reduce risk of console/clipboard manipulation via crafted URLs.

Event History

Oct 27, 2025
CVE Published
via MITRE·05:29 PM
Data Sourced
via MITRE·05:29 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
Affected Software
Advisory Published
via GitHub·06:31 PM
Data Sourced
via GitHub·06:31 PM
DescriptionSeverityWeaknessAffected Software
Dec 9, 2025
News Published
via BleepingComputer·10:41 PM
News Published
via BleepingComputer·10:42 PM
Jul 7, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-55754?

The severity of CVE-2025-55754 is classified as medium due to improper neutralization of escape sequences in log messages.

2

How do I fix CVE-2025-55754?

To fix CVE-2025-55754, upgrade to Apache Tomcat version 11.0.11 or later, 10.1.45 or later, or 9.0.109 or later.

3

What versions of Apache Tomcat are affected by CVE-2025-55754?

CVE-2025-55754 affects Apache Tomcat versions from 8.5.60 to 8.5.100, as well as 9.0.40 to 9.0.108, 10.1.0-M1 to 10.1.44, and 11.0.0-M1 to 11.0.10.

4

What is the impact of CVE-2025-55754 on users?

The impact of CVE-2025-55754 allows potentially malicious ANSI escape sequences to be processed and displayed in console logs, posing a risk to information exposure.

5

Is CVE-2025-55754 exploitable remotely?

CVE-2025-55754 is not directly exploitable remotely as it relies on specific conditions in the console environment where Tomcat runs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203