CVE-2025-54090
published 2025-07-23CVE-2025-54090: A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which…
PriorityP337medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.69%
48.5th percentile
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".
Users are recommended to upgrade to version 2.4.65, which fixes the issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | — | — |
| debian | apache2 | < apache2 2.4.65-1 (forky) | apache2 2.4.65-1 (forky) |
| msrc | azl3_httpd_2.4.64-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_httpd_2.4.65-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_httpd_2.4.64-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_httpd_2.4.65-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
osv6.3MEDIUM
vendor_apache6.3
vendor_debian6.3LOW
vendor_msrc6.3MEDIUM
vendor_oracle6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) — CVE-2025-54090
vendor_oracle·2025-10-15·CVSS 6.3
CVE-2025-54090 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) — CVE-2025-54090
Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) vulnerability
CVE: CVE-2025-54090
CVSS: 6.3
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Red Hat
httpd: Apache HTTP Server logic flaw
vendor_redhat·2025-07-23·CVSS 6.3
CVE-2025-54090 [MEDIUM] CWE-253 httpd: Apache HTTP Server logic flaw
httpd: Apache HTTP Server logic flaw
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".
Users are recommended to upgrade to version 2.4.65, which fixes the issue.
A logic flaw has been discovered in Apache HTTP Server version 2.4.64. This vulnerability causes RewriteCond expr directives to always evaluate as true, regardless of the actual condition. This could lead to unintended routing, access control bypasses, or other security policy violations if an administrator relies on these expressions for security enforcement. It is crucial to note that this issue specifically impacts only version 2.4.64; all other versions are unaffected.
Mitigation: Mitigation for this issue is either not available or the currently available options do not me
Microsoft
Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64
vendor_msrc·2025-07-08·CVSS 6.3
CVE-2025-54090 [MEDIUM] CWE-253 Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64
Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Refe
Debian
CVE-2025-54090: apache2 - A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests e...
vendor_debian·2025·CVSS 6.3
CVE-2025-54090 [MEDIUM] CVE-2025-54090: apache2 - A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests e...
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 2.4.65-1)
sid: resolved (fixed in 2.4.65-1)
trixie: resolved (fixed in 2.4.65-1)
Apache
Apache httpd: CVE-2025-54090
vendor_apache·CVSS 6.3
CVE-2025-54090 Apache httpd: CVE-2025-54090
Apache httpd: CVE-2025-54090
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. Reported to security team 2025-07-16 Update 2.4.65 released 2025-07-23 Affects 2.4.64
Severity: moderate
Affected versions: 2.4.65,
OSV
CVE-2025-54090: A bug in Apache HTTP Server 2
osv·2025-07-23·CVSS 6.3
CVE-2025-54090 [MEDIUM] CVE-2025-54090: A bug in Apache HTTP Server 2
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".
Users are recommended to upgrade to version 2.4.65, which fixes the issue.
GHSA
GHSA-cjqj-vhhm-xq5x: A bug in Apache HTTP Server 2
ghsa_unreviewed·2025-07-23
CVE-2025-54090 [MEDIUM] CWE-253 GHSA-cjqj-vhhm-xq5x: A bug in Apache HTTP Server 2
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".
Users are recommended to upgrade to version 2.4.65, which fixes the issue.
OSV
CVE-2025-54090: A bug in Apache HTTP Server 2
osv·2025-07-23·CVSS 6.3
CVE-2025-54090 [MEDIUM] CVE-2025-54090: A bug in Apache HTTP Server 2
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-23
Published