Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2025-24813: Apache Tomcat Remote Code Execution and Data Exposure
Known exploited
Exploitation likelihood: 100%
CVE-2025-24813
CVE-2025-24813
GHSA-83qj-6fr2-vhqg
BIT-tomcat-2025-24813
CVE-2025-24813
Summary
Apache Tomcat servers may be exploited by an attacker sending a specific type of HTTP request. This could potentially allow the attacker to execute malicious code, access sensitive data, or inject unwanted content. Update Apache Tomcat to the latest version to mitigate this risk.
What to do
- Update apache org.apache.tomcat:tomcat-catalina to version 11.0.3.
- Update apache org.apache.tomcat:tomcat-catalina to version 10.1.35.
- Update apache org.apache.tomcat:tomcat-catalina to version 9.0.99.
- Update apache org.apache.tomcat.embed:tomcat-embed-core to version 11.0.3.
- Update apache org.apache.tomcat.embed:tomcat-embed-core to version 10.1.35.
- Update apache org.apache.tomcat.embed:tomcat-embed-core to version 9.0.99.
- Update tomcat to version 11.0.3.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | apache | tomcat |
< 9.0.99 >= 10.1.1, < 10.1.35 >= 11.0.1, < 11.0.3 10.1.0 11.0.0 |
| maven | apache | org.apache.tomcat:tomcat-catalina |
>= 11.0.0-M1, < 11.0.3 >= 10.1.0-M1, < 10.1.35 >= 9.0.0.M1, < 9.0.99 >= 8.5.0, <= 8.5.100 Fix: upgrade to 11.0.3
|
| maven | apache | org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.3 >= 10.1.0-M1, < 10.1.35 >= 9.0.0.M1, < 9.0.99 >= 8.5.0, <= 8.5.100 Fix: upgrade to 11.0.3
|
| Bitnami | – | tomcat |
>= 11.0.0, < 11.0.3 Fix: upgrade to 11.0.3
|
| – | debian | debian_linux |
11.0 cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
| – | netapp | bootstrap_os |
All versions
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:* |
Original title
Apache Tomcat Path Equivalence Vulnerability
Original description
Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.
Vulnerability type
CWE-44
CWE-502
Deserialization of Untrusted Data
CWE-706
- https://nvd.nist.gov/vuln/detail/CVE-2025-24813
- https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq
- http://www.openwall.com/lists/oss-security/2025/03/10/5
- https://github.com/apache/tomcat/commit/0a668e0c27f2b7ca0cc7c6eea32253b9b5ecb29c
- https://github.com/apache/tomcat/commit/eb61aade8f8daccaecabf07d428b877975622f72
- https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc
- https://github.com/absholi7ly/POC-CVE-2025-24813/blob/main/README.md
- https://www.vicarius.io/vsociety/posts/cve-2025-24813-detect-apache-tomcat-rce
- https://www.vicarius.io/vsociety/posts/cve-2025-24813-mitigate-apache-tomcat-rce
- https://security.netapp.com/advisory/ntap-20250321-0001
- https://lists.debian.org/debian-lts-announce/2025/04/msg00003.html
- https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-detect-vulnerabilit...
- https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-mitigation-vulnerab...
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-...
- https://github.com/advisories/GHSA-83qj-6fr2-vhqg
- https://security.netapp.com/advisory/ntap-20250321-0001/ Third Party Advisory
Published: 1 Apr 2025 · Updated: 15 Jun 2026 · First seen: 6 Mar 2026