CVE-2025-55754 is a critical Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat versions 11.0.0-M1 through 11.0.10, 10.1.0-M1 through 10.1.44, and 9.0.40 through 9.0.108. An attacker could inject ANSI escape sequences into log messages via a specially crafted URL, potentially manipulating the console and clipboard on Windows systems to trick administrators into running malicious commands. With a CVSS score of 9.6 (CRITICAL), this vulnerability has a high impact on confidentiality, integrity, and availability, though it requires user interaction. While no active exploitation or public exploit code is currently known, the vulnerability has garnered significant community discussion and media coverage, indicating potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.1.0-M1, <= 10.1.44CPE match | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 11.0.0-M1, <= 11.0.10CPE match | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 8.5.60, <= 8.5.100CPE match | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 9.0.40, <= 9.0.108CPE match | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 9.0.40, < 9.0.109CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
HP Device Manager Vulnerability Update (5.0.16)
Mar 9, 2026Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
Oct 27, 2025org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation
Oct 27, 2025