CVE-2025-66200
published 2025-12-05CVE-2025-66200: mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can…
PriorityP432medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
EPSS
0.59%
44.4th percentile
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.
This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.7 < 2.4.66 | 2.4.66 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.7 – 2.4.65 | — |
| debian | apache2 | < apache2 2.4.66-1~deb12u1 (bookworm) | apache2 2.4.66-1~deb12u1 (bookworm) |
| msrc | azl3_httpd_2.4.65-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_httpd_2.4.65-1_on_cbl_mariner_2.0 | — | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_apache5.4
vendor_debian5.4MEDIUM
vendor_msrc5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
apache2 regression
osv·2026-03-09·CVSS 7.5
[HIGH] apache2 regression
apache2 regression
USN-7968-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression in mod_md where the MDStapleOthers setting was
ignored which resulted in OCSP being broken for some domains. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2025-5809
OSV
apache2 vulnerabilities
osv·2026-01-19·CVSS 7.5
CVE-2025-55753 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2025-58098)
Mattias Åsander discovered that the Apache HTTP Server incorrectly
neutralized certain environment variables. This could result in
unexpectedly superseding variables calculated by the server for CGI
programs. (CVE-2025-65082)
Mattias Åsander discovered that the Apache HTTP Server incorr
GHSA
GHSA-3j3g-3pw9-9vcc: mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server
ghsa_unreviewed·2025-12-05
CVE-2025-66200 [MEDIUM] CWE-288 GHSA-3j3g-3pw9-9vcc: mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.
This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
OSV
CVE-2025-66200: mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server
osv·2025-12-05·CVSS 5.4
CVE-2025-66200 [MEDIUM] CVE-2025-66200: mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.
OSV
CVE-2025-66200: mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server
osv·2025-12-05·CVSS 5.4
CVE-2025-66200 [MEDIUM] CVE-2025-66200: mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.
This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2026-05-29·CVSS 7.3
CVE-2023-38709 [HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-8338-1 introduced a regression in Apache HTTP Server
USN-8338-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression that prevented mod_http2 from loading on Ubuntu
18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache HTTP Server incorrectly handled certain
response headers. An attacker could possibly use this issue to perform
HTTP response splitting attacks. This issue only affected Ubuntu 14.04
LTS. (CVE-2023-38709)
Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2
implementation did not properly reclaim memory when streams were reset by
clients. A remote attacker could possibly use this issue to cause
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-05-28·CVSS 7.3
CVE-2023-38709 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server incorrectly handled certain
response headers. An attacker could possibly use this issue to perform
HTTP response splitting attacks. This issue only affected Ubuntu 14.04
LTS. (CVE-2023-38709)
Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2
implementation did not properly reclaim memory when streams were reset by
clients. A remote attacker could possibly use this issue to cause Apache
HTTP Server to consume resources, leading to a denial of service. This
issue only affected Ubuntu 18.04 LTS. (CVE-2023-45802)
Keran Mu and Jianjun Chen discovered that Apache HTTP Server incorrectly
handled certain response headers.
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2026-03-09·CVSS 7.5
[HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-7968-1 introduced a regression in Apache HTTP Server
USN-7968-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression in mod_md where the MDStapleOthers setting was
ignored which resulted in OCSP being broken for some domains. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-01-19·CVSS 7.5
CVE-2025-65082 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2025-58098)
Mattias Åsander discovered that the Apache HTTP Server incorrectly
neutralized certain environment variables. This could result in
unexpectedly superseding variables calculated by the server for CGI
pro
Microsoft
Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo
vendor_msrc·2025-12-09·CVSS 5.4
CVE-2025-66200 [MEDIUM] CWE-288 Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo
Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo
vendor_redhat·2025-12-05·CVSS 5.4
CVE-2025-66200 [MEDIUM] CWE-305 httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo
httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.
This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
A permissions bypass flaw has been discovered in the apache HTTP server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising e
Debian
CVE-2025-66200: apache2 - mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTT...
vendor_debian·2025·CVSS 5.4
CVE-2025-66200 [MEDIUM] CVE-2025-66200: apache2 - mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTT...
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 2.4.66-1~deb12u1)
bullseye: resolved (fixed in 2.4.66-1~deb11u1)
forky: resolved (fixed in 2.4.66-1)
sid: resolved (fixed in 2.4.66-1)
trixie: resolved (fixed in 2.4.66-1~deb13u1)
Apache
Apache httpd: CVE-2025-66200
vendor_apache·CVSS 5.4
CVE-2025-66200 Apache httpd: CVE-2025-66200
Apache httpd: CVE-2025-66200
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue. Acknowledgements: finder: Mattias Åsander (Umeå University) Reported to security team 2025-11-19 Update 2.4.66 released 2025-12-04 Affects 2.4.7 through 2.4.65
Severity: moderate
Affected versions: 2.4.65.
No detection rules found.
No public exploits indexed.
Wiz
ELSA-2025-23919 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.3
[HIGH] ELSA-2025-23919 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2025-23919 :
Apache HTTP Server vulnerability analysis and mitigation
ELSA-2025-23919: httpd security update (IMPORTANT)
Source : NVD
Published December 22, 2025
Severity HIGH
CNA Score N/A
Affected Technologies
Apache HTTP Server
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
httpd-filesystem
httpd-manual
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Apache HTTP Server vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Pu
Bugzilla
CVE-2025-66200 httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo
bugzilla·2025-12-05·CVSS 5.4
CVE-2025-66200 [MEDIUM] CVE-2025-66200 httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo
CVE-2025-66200 httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.
This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:23732 https://access.redhat.com/errata/RHSA-2025:23732
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:23932 https://access.redhat.com/errata/RHSA-2025:23932
---
This is
2025-12-05
Published