Apache has issued a patch for a critical (CVSS 9.1) security vulnerability in Tomcat's RewriteValve that allows unauthenticated attackers to bypass access controls. Streaming infrastructure providers utilizing affected versions of Tomcat are advised to upgrade immediately to remediate the risk of unauthorized access.