Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-24813

99
FAUCET Score

CVE-2025-24813 is a critical path equivalence vulnerability in Apache Tomcat, affecting versions 11.0.0-M1 through 11.0.2, 10.1.0-M1 through 10.1.34, and 9.0.0.M1 through 9.0.98, with older EOL versions also impacted. This flaw can lead to remote code execution (RCE) or information disclosure, depending on specific server configurations. Rated with a CVSS score of 9.8 (Critical), successful exploitation requires specific conditions, including enabled write access for the default servlet and support for partial PUT requests. The vulnerability is actively exploited in the wild, with public exploit code available, including Metasploit modules and Nuclei templates, and has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 9.0.99CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 10.1.1, < 10.1.35CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 11.0.1, < 11.0.3CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
10.1.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:*
10.1.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:10.1.0:milestone10:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
99.94%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Added to KEV · Apr 1, 2025
Metasploit: Tomcat Partial PUT Java Deserialization · Mar 10, 2025
Nuclei: CVE-2025-24813 · Mar 12, 2025
ExploitDB: EDB-52134 · Apr 7, 2025
This CVE's current EPSS score of 0.9994 is in the 100th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (34)

mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 10.1.35
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 9.0.99
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 10.1.35
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 11.0.3
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 9.0.99
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 11.0.3
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: tomcat-1:9.0.87-1.el9_2.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: tomcat-1:9.0.87-1.el9_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5Fixed in: tomcat
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.8 on RHEL 7Fixed in: jws5-tomcat-0:9.0.87-8.redhat_00008.1.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.8 on RHEL 8Fixed in: jws5-tomcat-0:9.0.87-8.redhat_00008.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.8 on RHEL 9Fixed in: jws5-tomcat-0:9.0.87-8.redhat_00008.1.el9jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 6.1 on RHEL 8Fixed in: jws6-tomcat-0:10.1.36-6.redhat_00007.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 6.1 on RHEL 9Fixed in: jws6-tomcat-0:10.1.36-6.redhat_00007.1.el9jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 6Fixed in: tomcat
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: tomcat9-1:9.0.87-5.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: tomcat-1:10.1.36-1.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: tomcat-1:9.0.87-1.el8_10.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: tomcat-1:9.0.87-1.el8_8.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: tomcat-1:9.0.87-2.el9_5.1
View patch
avayavendor investigatingvia llm_extracted
azurevendor investigatingvia llm_extracted
View patch
barracudavendor investigatingvia llm_extracted
boschvendor investigatingvia llm_extracted
clamavvendor investigatingvia llm_extracted
consulvendor investigatingvia llm_extracted
curlvendor investigatingvia llm_extracted
View patch
freshrssvendor investigatingvia llm_extracted
openrefinevendor investigatingvia llm_extracted
View patch
opensourceposvendor investigatingvia llm_extracted
View patch
qdrantvendor investigatingvia llm_extracted
solarwindsvendor investigatingvia llm_extracted
View patch
symantecvendor investigatingvia llm_extracted
verbbvendor investigatingvia llm_extracted

Vendor Advisories (16)

qdrantllm-qdrant-0ed7bd371ccf7235

Apache Tomcat Remote Code Execution (CVE-2025-24813) Vulnerability

Mar 27, 2025
barracudallm-barracuda-3b94b06969e5e4cc

Apache Tomcat Remote Code Execution (CVE-2025-24813) Vulnerability

Mar 27, 2025
symantecllm-symantec-ff7054e8e15928e8

Apache Tomcat Remote Code Execution (CVE-2025-24813) Vulnerability

Mar 27, 2025
verbbllm-verbb-a92a309f3c68714a

Apache Tomcat Remote Code Execution (CVE-2025-24813) Vulnerability

Mar 27, 2025
consulllm-consul-bcf88a7f05396ed4

Apache Tomcat Remote Code Execution (CVE-2025-24813) Vulnerability

Mar 27, 2025
clamavllm-clamav-0b0ab5c288ae8b9c

Apache Tomcat Remote Code Execution (CVE-2025-24813) Vulnerability

Mar 27, 2025
boschllm-bosch-aac4618e74caaf5f

Apache Tomcat Remote Code Execution (CVE-2025-24813) Vulnerability

Mar 27, 2025
freshrssllm-freshrss-8b9251a677bd0c67

Apache Tomcat Remote Code Execution (CVE-2025-24813) Vulnerability

Mar 27, 2025
mavenGHSA-83qj-6fr2-vhqgcritical

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

Mar 10, 2025
redhatCVE-2025-24813Moderate

tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

Mar 10, 2025
openrefinellm-openrefine-bba85049a2c2d2fc

Apache Tomcat Vulnerability (CVE-2025-24813)

opensourceposllm-opensourcepos-9edd5f03d24cb42c

Apache Tomcat Vulnerability (CVE-2025-24813)

curlllm-curl-d52d5ab1dbc41fde

Apache Tomcat Vulnerability (CVE-2025-24813)

azurellm-azure-19b13dc61d5dc6a4

Apache Tomcat Vulnerability (CVE-2025-24813)

avayallm-avaya-f7605be8c02e1134

Apache Tomcat Vulnerability (CVE-2025-24813)

solarwindsllm-solarwinds-441e8ebdb1ce17ce

Apache Tomcat Vulnerability (CVE-2025-24813)

References

github.com / absholi7ly/POC-CVE-2025-24813/blob/main/README.md
Exploit
cisa.gov / known-exploited-vulnerabilities-catalog
Third Party AdvisoryUS Government Resource
lists.debian.org / debian-lts-announce/2025/04/msg00003.html
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20250321-0001
Third Party Advisory
vicarius.io / vsociety/posts/cve-2025-24813-detect-apache-tomcat-rce
Issue Tracking
vicarius.io / vsociety/posts/cve-2025-24813-mitigate-apache-tomcat-rce
Issue Tracking
vicarius.io / vsociety/posts/cve-2025-24813-tomcat-detect-vulnerability
Issue Tracking
vicarius.io / vsociety/posts/cve-2025-24813-tomcat-mitigation-vulnerability
Issue Tracking
openwall.com / lists/oss-security/2025/03/10/5
Mailing ListThird Party Advisory
lists.apache.org / thread/j5fkjv2k477os90nczf2v9l61fb0kkgq
Vendor Advisory