CVE-2025-65082
published 2025-12-05CVE-2025-65082: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache…
PriorityP339medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.77%
51.5th percentile
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.
This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.
Users are recommended to upgrade to version 2.4.66 which fixes the issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.0 < 2.4.66 | 2.4.66 |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.65 | — |
| debian | apache2 | < apache2 2.4.66-1~deb12u1 (bookworm) | apache2 2.4.66-1~deb12u1 (bookworm) |
| msrc | azl3_httpd_2.4.65-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_httpd_2.4.65-1_on_cbl_mariner_2.0 | — | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2026-05-29·CVSS 7.3
CVE-2023-38709 [HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-8338-1 introduced a regression in Apache HTTP Server
USN-8338-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression that prevented mod_http2 from loading on Ubuntu
18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache HTTP Server incorrectly handled certain
response headers. An attacker could possibly use this issue to perform
HTTP response splitting attacks. This issue only affected Ubuntu 14.04
LTS. (CVE-2023-38709)
Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2
implementation did not properly reclaim memory when streams were reset by
clients. A remote attacker could possibly use this issue to cause
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-05-28·CVSS 7.3
CVE-2023-38709 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server incorrectly handled certain
response headers. An attacker could possibly use this issue to perform
HTTP response splitting attacks. This issue only affected Ubuntu 14.04
LTS. (CVE-2023-38709)
Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2
implementation did not properly reclaim memory when streams were reset by
clients. A remote attacker could possibly use this issue to cause Apache
HTTP Server to consume resources, leading to a denial of service. This
issue only affected Ubuntu 18.04 LTS. (CVE-2023-45802)
Keran Mu and Jianjun Chen discovered that Apache HTTP Server incorrectly
handled certain response headers.
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2026-03-09·CVSS 7.5
[HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-7968-1 introduced a regression in Apache HTTP Server
USN-7968-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression in mod_md where the MDStapleOthers setting was
ignored which resulted in OCSP being broken for some domains. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-01-19·CVSS 7.5
CVE-2025-65082 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2025-58098)
Mattias Åsander discovered that the Apache HTTP Server incorrectly
neutralized certain environment variables. This could result in
unexpectedly superseding variables calculated by the server for CGI
pro
Oracle
Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (Apache HTTP Server) — CVE-2025-65082
vendor_oracle·2026-01-15·CVSS 6.5
CVE-2025-65082 [MEDIUM] Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (Apache HTTP Server) — CVE-2025-65082
Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (Apache HTTP Server) vulnerability
CVE: CVE-2025-65082
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Microsoft
Apache HTTP Server: CGI environment variable override
vendor_msrc·2025-12-09·CVSS 6.5
CVE-2025-65082 [MEDIUM] CWE-150 Apache HTTP Server: CGI environment variable override
Apache HTTP Server: CGI environment variable override
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
httpd: Apache HTTP Server: CGI environment variable override
vendor_redhat·2025-12-05·CVSS 6.5
CVE-2025-65082 [MEDIUM] CWE-150 httpd: Apache HTTP Server: CGI environment variable override
httpd: Apache HTTP Server: CGI environment variable override
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.
This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.
Users are recommended to upgrade to version 2.4.66 which fixes the issue.
A configuration override flaw has been discovered in the apache HTTP server. Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.
Mitigation: Mitigation for this issue is e
Debian
CVE-2025-65082: apache2 - Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in A...
vendor_debian·2025·CVSS 6.5
CVE-2025-65082 [MEDIUM] CVE-2025-65082: apache2 - Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in A...
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.
Scope: local
bookworm: resolved (fixed in 2.4.66-1~deb12u1)
bullseye: resolved (fixed in 2.4.66-1~deb11u1)
forky: resolved (fixed in 2.4.66-1)
sid: resolved (fixed in 2.4.66-1)
trixie: resolved (fixed in 2.4.66-1~deb13u1)
OSV
apache2 regression
osv·2026-03-09·CVSS 7.5
[HIGH] apache2 regression
apache2 regression
USN-7968-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression in mod_md where the MDStapleOthers setting was
ignored which resulted in OCSP being broken for some domains. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2025-5809
OSV
apache2 vulnerabilities
osv·2026-01-19·CVSS 7.5
CVE-2025-55753 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2025-58098)
Mattias Åsander discovered that the Apache HTTP Server incorrectly
neutralized certain environment variables. This could result in
unexpectedly superseding variables calculated by the server for CGI
programs. (CVE-2025-65082)
Mattias Åsander discovered that the Apache HTTP Server incorr
OSV
CVE-2025-65082: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache con
osv·2025-12-05·CVSS 6.5
CVE-2025-65082 [MEDIUM] CVE-2025-65082: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache con
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.
GHSA
GHSA-768g-4qpg-32w7: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache con
ghsa_unreviewed·2025-12-05
CVE-2025-65082 [MEDIUM] CWE-150 GHSA-768g-4qpg-32w7: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache con
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.
This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.
Users are recommended to upgrade to version 2.4.66 which fixes the issue.
OSV
CVE-2025-65082: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache con
osv·2025-12-05·CVSS 6.5
CVE-2025-65082 [MEDIUM] CVE-2025-65082: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache con
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.
This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.
Users are recommended to upgrade to version 2.4.66 which fixes the issue.
No detection rules found.
No public exploits indexed.
Wiz
ELSA-2025-23919 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.3
[HIGH] ELSA-2025-23919 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2025-23919 :
Apache HTTP Server vulnerability analysis and mitigation
ELSA-2025-23919: httpd security update (IMPORTANT)
Source : NVD
Published December 22, 2025
Severity HIGH
CNA Score N/A
Affected Technologies
Apache HTTP Server
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
httpd-filesystem
httpd-manual
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Apache HTTP Server vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Pu
Bugzilla
CVE-2025-65082 httpd: Apache HTTP Server: CGI environment variable override
bugzilla·2025-12-05·CVSS 6.5
CVE-2025-65082 [MEDIUM] CVE-2025-65082 httpd: Apache HTTP Server: CGI environment variable override
CVE-2025-65082 httpd: Apache HTTP Server: CGI environment variable override
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.
This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.
Users are recommended to upgrade to version 2.4.66 which fixes the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:23732 https://access.redhat.com/errata/RHSA-2025:23732
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:23932 https://access.redhat.com/errata/RHSA-2025:23932
---
This i
2025-12-05
Published