Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
We have discovered 5,320 live websites that are affected by CVE-2026-59083.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 5,320 live websites (66% of Apache Tomcat install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 236 versions ( 61% of all versions) |
| 1,847 websites | |
| 961 websites | |
| 372 websites | |
| 161 websites | |
| 156 websites | |
| 120 websites | |
| 105 websites | |
| 97 websites | |
| 90 websites |
| .com | 2,216 websites |
| .de | 255 websites |
| .edu | 232 websites |
| .net | 196 websites |
| .cn | 192 websites |
| .org | 190 websites |
| .it | 140 websites |
| .com.br | 136 websites |
| .com.cn | 88 websites |
| .cz | 64 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.***.edu | *** | ||
| **************.com | **,*** | ||
| **.***.*****.*****.***.com | **,*** | ||
| *****.********.com | **,*** | ||
| **.******.com | **,*** | ||
| ************.com | **,*** | ||
| ***.*******.com | **,*** | ||
| ***.*********.edu | **,*** | ||
| ******.com | **,*** | ||
| ********.*********.com | **,*** |
FAQ