CVE-2025-58098
published 2025-12-05CVE-2025-58098: Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec…
PriorityP354high8.3CVSS 3.1
AVNACLPRLUINSUCHIHAL
EPSS
1.53%
72.1th percentile
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.
This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | < 2.4.66 | 2.4.66 |
| apache_software_foundation | apache_http_server | < 2.4.66 | 2.4.66 |
| debian | apache2 | < apache2 2.4.66-1~deb12u1 (bookworm) | apache2 2.4.66-1~deb12u1 (bookworm) |
| msrc | azl3_httpd_2.4.65-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_kernel_6.6.85.1-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_kernel_6.6.92.2-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_httpd_2.4.65-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0 | — | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
osv8.3HIGH
vendor_debian8.3HIGH
vendor_msrc8.3HIGH
vendor_redhat8.3HIGH
vendor_ubuntu7.5HIGH
vendor_oracle6.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2026-05-29·CVSS 7.3
CVE-2023-38709 [HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-8338-1 introduced a regression in Apache HTTP Server
USN-8338-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression that prevented mod_http2 from loading on Ubuntu
18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache HTTP Server incorrectly handled certain
response headers. An attacker could possibly use this issue to perform
HTTP response splitting attacks. This issue only affected Ubuntu 14.04
LTS. (CVE-2023-38709)
Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2
implementation did not properly reclaim memory when streams were reset by
clients. A remote attacker could possibly use this issue to cause
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-05-28·CVSS 7.3
CVE-2023-38709 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server incorrectly handled certain
response headers. An attacker could possibly use this issue to perform
HTTP response splitting attacks. This issue only affected Ubuntu 14.04
LTS. (CVE-2023-38709)
Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2
implementation did not properly reclaim memory when streams were reset by
clients. A remote attacker could possibly use this issue to cause Apache
HTTP Server to consume resources, leading to a denial of service. This
issue only affected Ubuntu 18.04 LTS. (CVE-2023-45802)
Keran Mu and Jianjun Chen discovered that Apache HTTP Server incorrectly
handled certain response headers.
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2026-03-09·CVSS 7.5
[HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-7968-1 introduced a regression in Apache HTTP Server
USN-7968-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression in mod_md where the MDStapleOthers setting was
ignored which resulted in OCSP being broken for some domains. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-01-19·CVSS 7.5
CVE-2025-65082 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2025-58098)
Mattias Åsander discovered that the Apache HTTP Server incorrectly
neutralized certain environment variables. This could result in
unexpectedly superseding variables calculated by the server for CGI
pro
Oracle
Oracle Oracle Communications Risk Matrix: Core (Apache HTTP Server) — CVE-2025-58098
vendor_oracle·2026-01-15·CVSS 6.4
CVE-2025-58098 [HIGH] Oracle Oracle Communications Risk Matrix: Core (Apache HTTP Server) — CVE-2025-58098
Oracle Oracle Communications Risk Matrix: Core (Apache HTTP Server) vulnerability
CVE: CVE-2025-58098
CVSS: 6.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Microsoft
Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...
vendor_msrc·2025-12-09·CVSS 8.3
CVE-2025-58098 [HIGH] CWE-201 Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...
Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...
vendor_redhat·2025-12-05·CVSS 8.3
CVE-2025-58098 [HIGH] CWE-201 httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...
httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.
This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
A server side include handling flaw has been discovered in the Apache HTTP server. When Server Side Includes (SSI) areenabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives an attacker may be able to inject commands executed by the server.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red
Microsoft
bpf: track changes_pkt_data property for global functions
vendor_msrc·2025-05-13·CVSS 5.5
CVE-2024-58098 [MEDIUM] bpf: track changes_pkt_data property for global functions
bpf: track changes_pkt_data property for global functions
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://lea
Debian
CVE-2025-58098: apache2 - Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled an...
vendor_debian·2025·CVSS 8.3
CVE-2025-58098 [HIGH] CVE-2025-58098: apache2 - Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled an...
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 2.4.66-1~deb12u1)
bullseye: resolved (fixed in 2.4.66-1~deb11u1)
forky: resolved (fixed in 2.4.66-1)
sid: resolved (fixed in 2.4.66-1)
trixie: resolved (fixed in 2.4.66-1~deb13u1)
OSV
apache2 regression
osv·2026-03-09·CVSS 7.5
[HIGH] apache2 regression
apache2 regression
USN-7968-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression in mod_md where the MDStapleOthers setting was
ignored which resulted in OCSP being broken for some domains. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2025-5809
OSV
apache2 vulnerabilities
osv·2026-01-19·CVSS 7.5
CVE-2025-55753 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2025-58098)
Mattias Åsander discovered that the Apache HTTP Server incorrectly
neutralized certain environment variables. This could result in
unexpectedly superseding variables calculated by the server for CGI
programs. (CVE-2025-65082)
Mattias Åsander discovered that the Apache HTTP Server incorr
OSV
CVE-2025-58098: Apache HTTP Server 2
osv·2025-12-05·CVSS 8.3
CVE-2025-58098 [HIGH] CVE-2025-58098: Apache HTTP Server 2
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.
GHSA
GHSA-4m29-g52g-c6qc: Apache HTTP Server 2
ghsa_unreviewed·2025-12-05
CVE-2025-58098 [HIGH] CWE-201 GHSA-4m29-g52g-c6qc: Apache HTTP Server 2
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.
This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
OSV
CVE-2025-58098: Apache HTTP Server 2
osv·2025-12-05·CVSS 8.3
CVE-2025-58098 [HIGH] CVE-2025-58098: Apache HTTP Server 2
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.
This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
No detection rules found.
No public exploits indexed.
Wiz
ELSA-2025-23919 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.3
[HIGH] ELSA-2025-23919 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2025-23919 :
Apache HTTP Server vulnerability analysis and mitigation
ELSA-2025-23919: httpd security update (IMPORTANT)
Source : NVD
Published December 22, 2025
Severity HIGH
CNA Score N/A
Affected Technologies
Apache HTTP Server
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
httpd-filesystem
httpd-manual
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Apache HTTP Server vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Pu
Bugzilla
CVE-2025-58098 httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...
bugzilla·2025-12-05·CVSS 8.3
CVE-2025-58098 [HIGH] CVE-2025-58098 httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...
CVE-2025-58098 httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.
This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:23732 https://access.redhat.com/errata/RHSA-2025:23732
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:23932 https://access.redhat.com/errata/RHSA-2025:23932
---
This issue has been addressed in the following products:
2025-12-05
Published