CVE-2025-54090

A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:2.4.64:*:*:*:*:*:*:*

History

14 Aug 2025, 00:47

Type Values Removed Values Added
First Time Apache http Server
Apache
CPE cpe:2.3:a:apache:http_server:2.4.64:*:*:*:*:*:*:*
References () https://news.ycombinator.com/item?id=44666896 - () https://news.ycombinator.com/item?id=44666896 - Issue Tracking, Patch
References () https://httpd.apache.org/security/vulnerabilities_24.html - () https://httpd.apache.org/security/vulnerabilities_24.html - Release Notes

27 Jul 2025, 02:15

Type Values Removed Values Added
CWE CWE-253
References
  • () https://news.ycombinator.com/item?id=44666896 -

23 Jul 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-23 14:15

Updated : 2025-08-14 00:47


NVD link : CVE-2025-54090

Mitre link : CVE-2025-54090


JSON object : View

Products Affected

apache

  • http_server
CWE

No CWE.