8.3
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Description
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.
This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Basic Information
ID
CVE-2025-58098
Source
apache
Published
Dec 5, 2025 at 13:40
Modified
Dec 5, 2025 at 16:06
Affected Product
Vendor
Apache Software Foundation
Product
Apache HTTP Server
Affected Versions
Apache Software Foundation Apache HTTP Server 0