Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.

This issue affects Apache HTTP Server before 2.4.66.

Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 09 Dec 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 08 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

Fri, 05 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache http Server
Vendors & Products Apache
Apache http Server

Fri, 05 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
References

Fri, 05 Dec 2025 13:45:00 +0000

Type Values Removed Values Added
Description Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Title Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...
Weaknesses CWE-201
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-12-05T16:06:22.201Z

Reserved: 2025-08-22T18:38:51.070Z

Link: CVE-2025-58098

cve-icon Vulnrichment

Updated: 2025-12-05T14:05:34.041Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-05T14:15:49.153

Modified: 2025-12-08T19:36:05.920

Link: CVE-2025-58098

cve-icon Redhat

Severity : Important

Publid Date: 2025-12-05T13:40:39Z

Links: CVE-2025-58098 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-12-05T20:56:14Z

Weaknesses