← Vulnerability feed

Vulnerability record · CVE-2025-24813 · published 10 March 2025

CVE-2025-24813: Apache Tomcat Default Servlet path equivalence enables RCE and file disclosure

Apache · Tomcat

Apache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Default Servlet when writes are enabled. Under specific configurations this leads to remote code execution via deserialization or to disclosure and injection of security-sensitive files.

9.8 CVSS 3.1 Critical CISA KEV since 1 Apr 2025 EPSS 100% · top 0.1% CWE-44 · CWE-44CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
10References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, KEV-listed with a near-certain EPSS score, and public exploit code make this an urgent remote code execution risk.

What it is

Apache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Default Servlet when writes are enabled. Under specific configurations this leads to remote code execution via deserialization or to disclosure and injection of security-sensitive files.

Impact

An attacker can read security-sensitive files, inject content into them, or achieve remote code execution in the Tomcat process, potentially compromising the host and any data it serves.

Attack surface

Reachable over the network through HTTP requests to the Default Servlet; no authentication or user interaction is required per the CVSS vector, but exploitation depends on non-default configuration such as writes enabled for the Default Servlet.

Exploitation

CISA added it to KEV on 2025-04-01 with a 2025-04-22 remediation due date, EPSS 30-day probability is 0.99927 (99.97th percentile), and a public proof-of-concept is referenced, indicating active exploitation.

What to do

  • Upgrade to Apache Tomcat 11.0.3, 10.1.35, or 9.0.99 as directed by the vendor advisory.
  • Disable write access for the Default Servlet (readonly=true) where it is not required.
  • Disable partial PUT support if it is not needed by the application.
  • Move file-based session persistence away from the default storage location or avoid it where possible.
  • Remove unnecessary deserialization-capable libraries from the classpath.

Detection

  • Monitor for HTTP PUT requests with partial content (Content-Range) targeting the Default Servlet or unusual paths containing internal dots.
  • Alert on unexpected file creation or modification in Tomcat web application, upload, and session persistence directories.
  • Watch for deserialization activity or anomalous child processes spawned by the Tomcat JVM.
  • Audit Tomcat configuration for enabled Default Servlet writes and partial PUT support.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-24813 to the Known Exploited Vulnerabilities catalog on 1 April 2025 as "Apache Tomcat Path Equivalence Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 22 April 2025.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-24813 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed

Source: NIST National Vulnerability Database (record CVE-2025-24813), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.