CVE-2025-24813: critical vulnerability in Apache Tomcat
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Apache Tomcat has a critical vulnerability in its file upload feature that can allow attackers to read sensitive files, modify uploaded content, or run malicious code on the server if certain features are enabled. This happens because the server doesn't properly validate file paths when handling partial uploads.
CVE-2025-24813 exploits path equivalence via dot-based naming in partial PUT requests to the default servlet. With writes enabled and partial PUT support active, attackers can traverse to sensitive file directories, read/modify files, or achieve RCE through deserialization when file-based session persistence is configured. The vulnerability affects Tomcat 9.0.0–9.0.98, 10.1.0–10.1.34, and 11.0.0–11.0.2.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.