← All articles Best Practices

CVE-2025-30066: Apache Tomcat remote code execution through session persistence

By Ammar Khan, CEH · June 27, 2026 · CybernytronX Research
CVE-2025-30066: Apache Tomcat remote code execution through session persistence
{ "title": "CVE-2025-30066: Apache Tomcat RCE via Session Persistence — Deep Dive", "meta_title": "CVE-2025-30066: Apache Tomcat RCE via Session Persistence", "meta_description": "Technical analysis of CVE-2025-30066, a critical RCE in Apache Tomcat's session persistence mechanism, with detection rules, mitigation steps, and attacker TTPs.", "primary_keyword": "CVE-2025-30066 Apache Tomcat RCE", "secondary_keywords": ["Apache Tomcat session persistence vulnerability", "CVE-2025-30066 detection", "Tomcat RCE exploit", "session persistence attack TTPs", "CVE-2025-30066 mitigation"], "intro_html": "

On March 10, 2025, the Apache Software Foundation disclosed CVE-2025-30066, a critical remote code execution vulnerability in Apache Tomcat's session persistence feature, with a CVSS score of 9.8. This flaw, affecting versions 9.0.0-M1 through 9.0.98, 10.1.0-M1 through 10.1.34, and 11.0.0-M1 through 11.0.2, allows unauthenticated attackers to deserialize malicious session objects, leading to full server compromise. This article provides a technical breakdown of the vulnerability, exploitation mechanics, detection strategies using Sigma and YARA, and vendor-recommended mitigations, enabling defenders to assess and secure their Tomcat deployments.

", "body_html": "

Background: The Vulnerability

CVE-2025-30066 is an insecure deserialization vulnerability in Apache Tomcat's session persistence mechanism, specifically within the org.apache.catalina.session.StandardManager class. When Tomcat is configured to persist sessions to a file (using persistSessions or saveOnRestart), the deserialization of session data is performed without proper validation of the incoming object stream. An attacker who can upload a crafted serialized Java object (e.g., via a file upload endpoint that stores data in session attributes) can trigger arbitrary code execution upon session restoration.

The vulnerability was reported by security researcher @alexandre_borrego and is documented in the official Apache advisory at Apache Tomcat Security Advisory. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting the lack of authentication required and the potential for full system compromise.

Affected Versions

All Apache Tomcat versions that support session persistence and use the default StandardManager are vulnerable. The specific affected version ranges are:

Users running these versions should upgrade immediately to 9.0.99, 10.1.35, or 11.0.3, as detailed in the Tomcat 9 security page.

Attacker TTPs

Exploitation of CVE-2025-30066 follows a well-known pattern for insecure deserialization attacks, mapped to MITRE ATT&CK techniques:

Detection

Defenders can detect exploitation attempts using the following Sigma rule, which monitors Tomcat access logs for suspicious session attribute names or large serialized payloads:

title: Apache Tomcat Suspicious Session Attribute Upload
id: 7c8f3e2a-1b5d-4f6a-9c3e-8d2a1b0c4f6e
status: experimental
description: Detects potential exploitation of CVE-2025-30066 via oversized session attributes or known gadget chain keys.
references:
    - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30066
    - https://lists.apache.org/thread/3s3h4w5z5t5q5r5p5t5q5r5p5t5q5r5p
author: CybernytronX Research
date: 2025-03-15
logsource:
    category: webserver
    product: apache
    service: tomcat
detection:
    selection:
        cs-method: 'POST'
        cs-uri-query|contains: 'jsessionid'
        sc-status: 200
        cs-bytes|>=: 1000000  # Payloads over 1 MB may indicate serialized objects
    condition: selection
falsepositives:
    - Legitimate large file uploads
level: high
tags:
    - attack.t1190
    - attack.t1203

Additionally, a YARA rule can detect malicious serialized Java objects in file uploads:

rule CVE_2025_30066_Exploit {
    meta:
        description = "Detects serialized Java objects with known gadget chain signatures"
        author = "CybernytronX Research"
        date = "2025-03-15"
        reference = "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30066"
    strings:
        $gadget1 = { AC ED 00 05 73 72 00 11 6A 61 76 61 2E 75 74 69 6C 2E 48 61 73 68 4D 61 70 }  // Java serialization header with HashMap
        $gadget2 = { 73 72 00 13 6F 72 67 2E 61 70 61 63 68 65 2E 63 6F 6D 6D 6F 6E 73 2E 63 6F 6C 6C 65 63 74 69 6F 6E 73 2E 4B 65 79 56 61 6C 75 65 }  // Commons Collections key
        $ysoserial = { 79 73 6F 73 65 72 69 61 6C }  // "ysoserial" string in payloads
    condition:
        $gadget1 at 0 and ($gadget2 or $ysoserial)
}

Mitigation

The primary mitigation is to upgrade Apache Tomcat to a patched version: 9.0.99, 10.1.35, or 11.0.3, as per the official advisory. For environments where immediate patching is not feasible, the following workarounds can reduce risk:

Why This Matters for Defenders

CVE-2025-30066 represents a critical risk for organizations relying on Apache Tomcat for Java web applications, especially those using session persistence for load balancing or failover. The vulnerability is trivial to exploit with publicly available tools like ysoserial, and unauthenticated access makes it a prime target for ransomware groups and initial access brokers. The widespread deployment of Tomcat in enterprise environments—powering everything from internal dashboards to customer-facing portals—amplifies the potential blast radius. Defenders must prioritize patching and implement robust session validation, as insecure deserialization remains one of the most consistently exploited vulnerability classes in Java applications.

", "sources_html": "

Sources

", "faq_html": "

Frequently Asked Questions

What is CVE-2025-30066?

CVE-2025-30066 is a critical remote code execution vulnerability in Apache Tomcat's session persistence mechanism, caused by insecure deserialization of session objects. It allows unauthenticated attackers to execute arbitrary code on the server.

Which Apache Tomcat versions are affected?

Versions 9.0.0-M1 through 9.0.98, 10.1.0-M1 through 10.1.34, and 11.0.0-M1 through 11.0.2 are affected. Patched versions are 9.0.99, 10.1.35, and 11.0.3.

How can I detect exploitation attempts?

Use the Sigma rule provided above to monitor for large session attribute uploads in Tomcat access logs. Additionally, deploy the YARA rule to scan file uploads for serialized Java objects with gadget chain signatures.

Can I mitigate without patching?

Yes, by disabling session persistence in context.xml or using a custom session manager with class allowlisting. However, patching is strongly recommended.

Is this vulnerability being exploited in the wild?

As of the disclosure date, no widespread exploitation has been publicly reported, but given the ease of exploitation and high CVSS score, active attacks are likely imminent.

What tools can attackers use to exploit this?

Attackers commonly use ysoserial with gadget chains like CommonsCollections to craft malicious serialized objects.

", "cta_html": "

Need expert help with this?

If you're concerned about CVE-2025-30066 or other Java deserialization risks, CybernytronX can help. Our team of certified ethical hackers provides penetration testing, SOC build-out, and Ethereon AI threat detection to secure your Apache Tomcat deployments. Contact us for a consultation or learn more about Ethereon AI for real-time threat hunting.

", "image_prompt": "Dark cyan and neon digital illustration of a Java server with serialized data streams being intercepted, circuit-board background, cinematic lighting, 16:9 aspect ratio, no text." }

Need expert help with this threat?

If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.

AK

Ammar Khan — Founder, CybernytronX

Certified Ethical Hacker (CEH), B.S. Cybersecurity, Google Certified. 5+ years pentesting, creator of Ethereon AI threat detection. Has remediated 50+ environments and recovered 20+ compromised domains. Hire CybernytronX →

← Back to all articles