This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4452-1 | apache2 security update |
Ubuntu USN |
USN-7968-1 | Apache HTTP Server vulnerabilities |
Thu, 26 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 09 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 08 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* |
Fri, 05 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache http Server |
|
| Vendors & Products |
Apache
Apache http Server |
Fri, 05 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 05 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 05 Dec 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue. | |
| Title | Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... | |
| Weaknesses | CWE-201 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-02-26T16:57:30.146Z
Reserved: 2025-08-22T18:38:51.070Z
Link: CVE-2025-58098
Updated: 2025-12-05T14:05:34.041Z
Status : Analyzed
Published: 2025-12-05T14:15:49.153
Modified: 2025-12-08T19:36:05.920
Link: CVE-2025-58098
OpenCVE Enrichment
Updated: 2025-12-05T20:56:14Z
Debian DLA
Ubuntu USN