Apache Under the Lens: Tomcat’s Partial PUT and Camel’s Header Hijack
ID: 762454d8-c51b-5f35-a499-db3af0b7b3ee
STIX ID: report--762454d8-c51b-5f35-a499-db3af0b7b3ee
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-07-03
Date Updated: 2026-04-28
Author: Jun Li, Qiang Liu, Yiheng An and Haozhe Zhang
Executive Summary: In March 2025 Apache disclosed three critical remote-code-execution vulnerabilities — CVE-2025-24813 in Apache Tomcat (abusing partial PUT and session persistence deserialization) and CVE-2025-27636/CVE-2025-29891 in Apache Camel (case-sensitive header filter bypass enabling execution). Palo Alto Networks Unit 42 validated exploitation steps, published PoCs, observed large-scale scanning and active exploit attempts (125,856 probes overall; 7,859 Tomcat attempts), and provided IOCs and mitigation guidance; organizations are advised to patch promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
