Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-54090

23
FAUCET Score

CVE-2025-54090 is a bug in Apache HTTP Server version 2.4.64 where all "RewriteCond expr ..." tests incorrectly evaluate as "true," potentially leading to unintended rewrite rule execution. This vulnerability has a CVSS score of 6.3 (Medium), indicating it can be exploited remotely with low complexity and user privileges, potentially impacting confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage. Users are advised to upgrade to Apache HTTP Server version 2.4.65 to remediate this issue.

Impacted Technologies

VendorProductVersion(s)CPE
2.4.64CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.4.64:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.69%
Probability of exploitation in next 30 days
EPSS Percentile
48.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0069 is in the 59th percentile among its peer group of 21,957 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

apachepatch availablevia llm_extracted
Fixed in: 2.4
gcppatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 19577-16823Fixed in: 2.4.65-1
microsoftpatch availablevia msrc
Product: 19625-17084Fixed in: 2.4.65-1
microsoftpatch availablevia msrc
Product: 19528-17084Fixed in: 2.4.65-1
microsoftpatch availablevia msrc
Product: 20350-17086Fixed in: 2.4.65-1
microsoftpatch availablevia msrc
Product: cbl2 httpd 2.4.65-1 on CBL Mariner 2.0Fixed in: 2.4.65-1
microsoftpatch availablevia msrc
Product: azl3 httpd 2.4.65-1 on Azure Linux 3.0Fixed in: 2.4.65-1
microsoftpatch availablevia msrc
Product: azl3 httpd 2.4.64-1 on Azure Linux 3.0Fixed in: 2.4.65-1
microsoftpatch availablevia msrc
Product: cbl2 httpd 2.4.64-1 on CBL Mariner 2.0Fixed in: 2.4.65-1

Vendor Advisories (6)

gcpllm-gcp-e028ccdedcbc6cccCRITICAL

HP Device Manager Vulnerability Update (5.0.16)

Mar 9, 2026
apachellm-apache-f398f8ed28802aa3LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Mar 2, 2026
apachellm-apache-a7a91ec4c0e9421dHIGH

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Dec 10, 2025
redhatCVE-2025-54090Moderate

httpd: Apache HTTP Server logic flaw

Jul 23, 2025
microsoft2025-Jul/CVE-2025-54090Moderate

Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64

Jul 8, 2025
apachellm-apache-684e4d0003611bd4LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

References

lists.debian.org / debian-lts-announce/2025/08/msg00009.html
news.ycombinator.com / item
Issue TrackingPatch
openwall.com / lists/oss-security/2025/07/24/2
httpd.apache.org / security/vulnerabilities_24.html
Release Notes