Sploitus

Exploit for Improper Encoding or Escaping of Output in Apache Tomcat CVE-2025-31651

githubexploit Β· 2025-04-08

Exploit Code

README11 lines
## https://sploitus.com/exploit?id=9422D1BC-13FB-52A1-80A9-D5C82DBEA084
# CVE-2025-31651
For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed.

## 0x01 Status
PUBLIC

## 0x02 PoC
[Finder](https://github.com/gregk4sec)

see [CVE-2025-31651.md](./CVE-2025-31651.md)