Improper Output Neutralization for Logs in Apache Tomcat - CVE-2025-55754
Published: October 27, 2025 / Updated: October 29, 2025
Apache Tomcat
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary OS commands.
The vulnerability exists due to improper input validation of ANSI escape sequences in log messages. A remote attacker can use a crafted URL to inject ANSI escape sequences to manipulate the console and the clip-boardand potentially execute arbitrary code.
The vulnerability affects Windows installations only.