logo

Apache Under the Lens: Tomcat’s Partial PUT and Camel’s Header Hijack

ID: 762454d8-c51b-5f35-a499-db3af0b7b3ee

STIX ID: report--762454d8-c51b-5f35-a499-db3af0b7b3ee

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2025-07-03

Date Updated: 2026-04-28

Author: Jun Li, Qiang Liu, Yiheng An and Haozhe Zhang

...
...

Executive Summary: In March 2025 Apache disclosed three critical remote-code-execution vulnerabilities — CVE-2025-24813 in Apache Tomcat (abusing partial PUT and session persistence deserialization) and CVE-2025-27636/CVE-2025-29891 in Apache Camel (case-sensitive header filter bypass enabling execution). Palo Alto Networks Unit 42 validated exploitation steps, published PoCs, observed large-scale scanning and active exploit attempts (125,856 probes overall; 7,859 Tomcat attempts), and provided IOCs and mitigation guidance; organizations are advised to patch promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.