cbcvebase.
CVE-2025-54090
published 2025-07-23

CVE-2025-54090: A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which…

medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.

Affected

8 ranges
VendorProductVersion rangeFixed in
apachehttp_server
apachehttpd
apache_software_foundationapache_http_server
debianapache2< apache2 2.4.65-1 (forky)apache2 2.4.65-1 (forky)
msrcazl3_httpd_2.4.64-1_on_azure_linux_3.0
msrcazl3_httpd_2.4.65-1_on_azure_linux_3.0
msrccbl2_httpd_2.4.64-1_on_cbl_mariner_2.0
msrccbl2_httpd_2.4.65-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
osv6.3MEDIUM