CVE-2025-58098

CWE-20112 documents9 sources
Severity
8.3HIGH
EPSS
0.0%
top 91.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 5
Latest updateJan 19

Description

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:LExploitability: 2.8 | Impact: 5.5

Affected Packages4 packages

NVDapache/http_server< 2.4.66
Alpineapache2< 2.4.66-r0+3
Debianapache2< 2.4.66-1~deb11u1+3

🔴Vulnerability Details

5
OSV
apache2 vulnerabilities2026-01-19
CVEList
Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...2025-12-05
OSV
CVE-2025-58098: Apache HTTP Server 22025-12-05
GHSA
GHSA-4m29-g52g-c6qc: Apache HTTP Server 22025-12-05
OSV
CVE-2025-58098: Apache HTTP Server 22025-12-05

📋Vendor Advisories

6
Ubuntu
Apache HTTP Server vulnerabilities2026-01-19
Oracle
Oracle Oracle Communications Risk Matrix: Core (Apache HTTP Server) — CVE-2025-580982026-01-15
Microsoft
Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...2025-12-09
Red Hat
httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...2025-12-05
Microsoft
bpf: track changes_pkt_data property for global functions2025-05-13