Exploit for Improper Encoding or Escaping of Output in Apache Tomcat CVE-2025-31651
Exploit Code
## https://sploitus.com/exploit?id=9422D1BC-13FB-52A1-80A9-D5C82DBEA084
# CVE-2025-31651
For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed.
## 0x01 Status
PUBLIC
## 0x02 PoC
[Finder](https://github.com/gregk4sec)
see [CVE-2025-31651.md](./CVE-2025-31651.md)