CVE-2025-24813

Apache Tomcat: Path Equivalence

As of , CVE-2025-24813 in Apache Tomcat is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 1 April 2025
US federal deadline
22 April 202521 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
1 Metasploit module and 1 Exploit-DB entry
Fix
Vendor advice: lists.apache.orgLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‐2026‐34486.

CISA's description

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.

The CVE record's description, from apache

CVE published
10 March 2025
Assigned by
apache
CVSS
10.0 Critical (CVSS 3.1, from CISA-ADP)
CWE-44
Path Equivalence: 'file.name' (Internal Dot)
CWE-502
Deserialization of Untrusted Data
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. Exploit-DB published an exploit (EDB-ID 52134).
  4. The US federal deadline to fix it.
  5. CISA changed its entry. Edited: notes.
  6. CISA changed its entry. Edited: description.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Tomcat: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2017-12617Remote Code ExecutionApache TomcatPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2020-1938Improper Privilege ManagementApache TomcatPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2016-8735Remote Code ExecutionApache TomcatPatch this weekEPSS 0.900.90
CVE-2017-12615on Windows Remote Code ExecutionApache TomcatPatch this weekRansomware use; EPSS 0.990.99
CVE-2026-34486Missing Encryption of Sensitive DataApache TomcatPatch soon0.07

Read further