CVE-2026-59083

Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.


We have discovered 5,320 live websites that are affected by CVE-2026-59083.

Run a Free Instant Scan




Affected Software

Product  Apache Tomcat
Category Web Servers
Vulnerable Domains5,320 live websites (66% of Apache Tomcat install base)
Vulnerable Versions
  • from 8.5 through 8.5.100
  • from 9 through 9.0.119
  • from 10.1 through 10.1.56
  • from 11 through 11.0.23
Vulnerable Versions Count236 versions ( 61% of all versions)


Common Weakness Enumeration

CWE-177 Improper Handling of URL Encoding (Hex Encoding)



Details

  • Published - Jul 14, 2026
  • Updated - Jul 14, 2026

Website Distribution by Country

Number of websites using CVE-2026-59083
United States1,847 websites



China961 websites
Germany372 websites
Italy161 websites
France156 websites
Brazil120 websites
GB105 websites
India97 websites
Hong Kong90 websites

Website Distribution by TLD

Number of websites using CVE-2026-59083
.com2,216 websites
.de255 websites
.edu232 websites
.net196 websites
.cn192 websites
.org190 websites
.it140 websites
.com.br136 websites
.com.cn88 websites
.cz64 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-59083

Top websites that are affected by CVE-2026-59083. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States***
**************.com United States**,***
**.***.*****.*****.***.com United States**,***
*****.********.com United States**,***
**.******.com United States**,***
************.com United States**,***
***.*******.com United States**,***
***.*********.edu United States**,***
******.com China**,***
********.*********.com United States**,***
See full domain list

FAQ

CVE-2026-59083 is Improper Handling of URL Encoding (Hex Encoding) in Apache Tomcat
A total of 5,320 websites have been identified as vulnerable to CVE-2026-59083, based on global website indexing conducted by WebTechSurvey.
The Apache Tomcat is affected by the CVE-2026-59083 vulnerability.
Apache Tomcat versions up to and including 11.0.23 are vulnerable to CVE-2026-59083.