RaqibCTI
CVE

CVE-2025-24813

P2
Apache Tomcat Path Equivalence Vulnerability
Apache · Tomcat
Date added (CISA)
2025-04-01
Remediation due
2025-04-22
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date
Associated with
Related to
  • Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaignCorrelated cluster2026-09-16

Description

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.

Source: NVD ↗ · CISA KEV Catalog ↗