Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 99.9%top 0.03%

CVE-2025-24813: CWE-44 Path Equivalence: 'file.name' (Internal Dot) in Apache Software Foundation Apache Tomcat

0
Critical
Published: 08/03/2026 (08/03/2026, 09:40:19 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache Tomcat

Description

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.

CVSS v3.1

Score 10.0critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected software

Affected versions
=11.0.0-M1=10.1.0-M1=8.5.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 02/27/2026, 12:37:11 UTC

Technical Analysis

CVE-2025-24813 is a critical security vulnerability affecting multiple versions of Apache Tomcat, a widely used Java servlet container. The root cause is a path equivalence issue related to internal dots in filenames (e.g., 'file.name') processed by the default servlet when write operations are enabled. This flaw allows attackers to bypass normal file path restrictions and manipulate file uploads via partial PUT requests, which are enabled by default. If the default servlet's write capability is enabled (disabled by default), and partial PUT support is active, an attacker who knows the names of security-sensitive files can upload or modify these files, leading to information disclosure or injection of malicious content. Furthermore, if the application uses Tomcat's file-based session persistence with the default storage location and includes a library vulnerable to deserialization attacks, the attacker can achieve remote code execution. This is due to the ability to overwrite session files or upload crafted payloads that trigger deserialization vulnerabilities. The vulnerability affects Apache Tomcat versions 8.5.0 through 8.5.100, 9.0.0.M1 through 9.0.98, 10.1.0-M1 through 10.1.34, and 11.0.0-M1 through 11.0.2. End-of-life versions are also affected. The issue is tracked under CWE-44 (Path Equivalence) and CWE-502 (Deserialization of Untrusted Data). The vulnerability has a CVSS v3.1 base score of 10.0, reflecting its critical impact on confidentiality, integrity, and availability without requiring authentication or user interaction. No known exploits are publicly reported yet. The recommended mitigation is upgrading to Apache Tomcat versions 11.0.3, 10.1.35, or 9.0.99, which contain patches addressing this vulnerability.

Potential Impact

The impact of CVE-2025-24813 is severe and multifaceted. Organizations running vulnerable Apache Tomcat versions with write-enabled default servlets and partial PUT support risk unauthorized disclosure of sensitive files, modification or injection of malicious content into uploaded files, and potentially full remote code execution. Remote code execution can lead to complete system compromise, enabling attackers to execute arbitrary commands, deploy malware, or move laterally within networks. The vulnerability undermines confidentiality, integrity, and availability of affected systems. Given Apache Tomcat's widespread use in enterprise web applications, government portals, and cloud services, exploitation could disrupt critical services, cause data breaches, and damage organizational reputation. The ease of exploitation (no authentication or user interaction required) and the broad scope of affected versions amplify the threat. Additionally, the reliance on file-based session persistence and vulnerable deserialization libraries in many Java applications increases the risk of remote code execution. Organizations failing to patch promptly may face targeted attacks, especially in sectors relying heavily on Java web infrastructure.

Mitigation Recommendations

To mitigate CVE-2025-24813, organizations should: 1) Immediately upgrade Apache Tomcat to versions 11.0.3, 10.1.35, or 9.0.99 or later, which contain the security fix. 2) Disable write access to the default servlet unless explicitly required; this is disabled by default and should remain so unless necessary. 3) Consider disabling or restricting partial PUT support if not essential for application functionality. 4) Review and harden file upload directories to ensure sensitive files are not stored in subdirectories accessible via public upload URLs. 5) Audit and update any libraries used for deserialization to versions without known vulnerabilities, or implement strict input validation and deserialization controls. 6) If file-based session persistence is used, consider migrating to alternative session management mechanisms or secure the session storage location with strict access controls. 7) Implement robust monitoring and logging to detect unusual file upload or modification activities. 8) Conduct thorough security testing and code reviews focusing on file upload handling and deserialization processes. These steps go beyond generic patching by addressing configuration and architectural factors that contribute to exploitation risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.1
Assigner Short Name
apache
Date Reserved
2025-01-24T08:51:50.296Z
Cvss Version
3.1
State
PUBLISHED

Indicators of Compromise

Ip

ValueDescriptionCopy
ip221.198.83.248
ip149.129.37.105
ip92.38.135.196
ip130.94.30.168
ip130.94.17.180

Cve

ValueDescriptionCopy
cveCVE-2025-24813

Url

ValueDescriptionCopy
urlhttp://139.0.0.0
urlhttp://130.94.30.168:8080
urlhttp://149.129.37.105:30005
urlhttp://92.38.135.196:8888

Hash

ValueDescriptionCopy
hashd7ed70cdd88f6cccbdc0ad6851d7a61b7fce79fdf9c4cd9f9bb375233a96b2dd
hash456233b58bcf8c17ef9ef44b14a966a6
hash71072a8c4adfcde49a4b163959a24283
hash8887c65035893d99996991282553fc19
hash913a572c1bf9da27ee7d21befa3cee0c
hash9ab45387111475d5cfb77fb4e49eba82bad7ca4d
hasha24b4bb466324459f40e6adbc5d481ec6cee48ef
hashb1f71014f4c0e1e61c0b3fe2391a6c6aa03ac3f9
hashd26f84a768062c52179216bf6ca4c551448890be
hash00b0cef237d9619c99c5d90cf902ec768c1ecf4f96d542d31dc5afb0b564cb4f
hash20e1ec6b07abe3b2dd54f7ae4e47dc00afa46de6e6c0ef0239c26c8bae70a43a
hash2ac6c953d2d36eb7e7e85aa0822a65961071f7801a25118ab42bcfa9693327a1
hash4738f3559c10f7c62a3be48ec2ce42c584b53d5ffa9e06e6521607a6fdfd535f
hash66543c4f9f4d610a79efa5e52b9aa90ca41dbfc154418435a2902ac48dad2ee4
hash75d39860a5c5ce6c26590265102f25c50f91a22b6769d22046759fb3aff8d0a8
hash9c59a0dadec1f1b73724f3ee4113e4fde696214371b9068fd69774db4cd8b8d2
hasha4989ae1d598e79a87a9e01d0b5966a25b00b23ca234fbdb52b9df7b29db918a
hashadde431d5b78b2b2cfb67c5bcd938be6cc466fbb3ac2786cad97b493f6fcfad5
hashb272e2e4a7c65f2659a8fff8ceec4d9538f74f6dc9bace7d051a4476ba6bc77c
hashb7486bb7fc5f7e659b40dab3366b576d68db61ca0004de7a1e115eb9b541f19a
hashb96cdf8bc96c7288af7624974b1a10b7bf16e5ac03ac8493ade20696a906a81a
hashc0a5374a425ee5030b2219520dfa3a3a51f27d3cc4404b016e695c4450fe3034
hashc2d0e4dd2f2b3f1d4eb4518984b00ed521c73d1e935780786479db690112ef9c
hashdc493eb8367b7d68f4d3d9f2a10c495c6a45c33df72fb5a18bdf62b629f69e31
hashebc94e24e4df94f988dd0a2275e8a3f1957051814a3c39ec30bfaca2f5ca2607

Domain

ValueDescriptionCopy
domaingoogle.chromeupgrades.com
domainspeedtest.qqmail.website

Threat ID: 687e795da83201eaac11f328

Added to database: 07/21/2025, 17:31:09 UTC

Last enriched: 02/27/2026, 12:37:11 UTC

Last updated: 08/03/2026, 10:35:46 UTC

Views: 277

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses