Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2025-24813: Apache Tomcat Remote Code Execution and Data Exposure

Known exploited Exploitation likelihood: 100%
CVE-2025-24813 CVE-2025-24813 GHSA-83qj-6fr2-vhqg BIT-tomcat-2025-24813 CVE-2025-24813
Summary

Apache Tomcat servers may be exploited by an attacker sending a specific type of HTTP request. This could potentially allow the attacker to execute malicious code, access sensitive data, or inject unwanted content. Update Apache Tomcat to the latest version to mitigate this risk.

What to do
  • Update apache org.apache.tomcat:tomcat-catalina to version 11.0.3.
  • Update apache org.apache.tomcat:tomcat-catalina to version 10.1.35.
  • Update apache org.apache.tomcat:tomcat-catalina to version 9.0.99.
  • Update apache org.apache.tomcat.embed:tomcat-embed-core to version 11.0.3.
  • Update apache org.apache.tomcat.embed:tomcat-embed-core to version 10.1.35.
  • Update apache org.apache.tomcat.embed:tomcat-embed-core to version 9.0.99.
  • Update tomcat to version 11.0.3.
Affected software
Ecosystem VendorProductAffected versions
apache tomcat < 9.0.99
>= 10.1.1, < 10.1.35
>= 11.0.1, < 11.0.3
10.1.0
11.0.0
maven apache org.apache.tomcat:tomcat-catalina >= 11.0.0-M1, < 11.0.3
>= 10.1.0-M1, < 10.1.35
>= 9.0.0.M1, < 9.0.99
>= 8.5.0, <= 8.5.100
Fix: upgrade to 11.0.3
maven apache org.apache.tomcat.embed:tomcat-embed-core >= 11.0.0-M1, < 11.0.3
>= 10.1.0-M1, < 10.1.35
>= 9.0.0.M1, < 9.0.99
>= 8.5.0, <= 8.5.100
Fix: upgrade to 11.0.3
Bitnami tomcat >= 11.0.0, < 11.0.3
Fix: upgrade to 11.0.3
debian debian_linux 11.0
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
netapp bootstrap_os All versions
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
Published: 1 Apr 2025 · Updated: 15 Jun 2026 · First seen: 6 Mar 2026