Apache Tomcat Security Update Advisory (CVE-2025-24813)

Overview

 

Apache Tomcat(https://tomcat.apache.org/) has released a security update that addresses a vulnerability in its shipped products. Users of affected products are advised to update to the latest version.

 

Affected Products

 

Apache Tomcat 9.0.0.M1 – 9.0.98

Apache Tomcat 10.1.0-M1 – 10.1.34

Apache Tomcat 11.0.0-M1 – 11.0.2

 

Resolved Vulnerabilities

 

Remote code execution, information disclosure, and malicious content addition vulnerability in Apache Tomcat (CVE-2025-24813)

 

Vulnerability Patches

 

Please follow the security advisory published on March 10, 2025 to update to the applicable version and the latest version.

Apache Tomcat 9.0.99

Apache Tomcat 10.1.35

Apache Tomcat 11.0.3

 

Referenced Sites

 

[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24813

[2] https://tomcat.apache.org/security