PT-2025-49182 · Apache+3 · Apache Http Server+3
Published
2025-09-10
·
Updated
2026-03-24
·
CVE-2025-59775
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions prior to 2.4.66
Description
An issue exists in Apache HTTP Server on Windows when
AllowEncodedSlashes is enabled and MergeSlashes is disabled. This can allow for Server-Side Request Forgery (SSRF), potentially leading to the leakage of NTLM hashes to a malicious server through crafted requests or content. The issue enables an attacker to make requests on behalf of the server, potentially accessing internal resources.Recommendations
Upgrade to version 2.4.66 to resolve this issue.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Http Server
Apple Macos
Red Os