A critical remote code execution (RCE) vulnerability in Apache Tomcat was disclosed on March 10, 2025.
As per the analysis from our engineering team, the Gateway does not utilize persistent sessions, the Gateway does not enable writes for the DefaultServlet, so it's not affected by this CVE.