CVE-2025-54090 is a bug in Apache HTTP Server version 2.4.64 where all "RewriteCond expr ..." tests incorrectly evaluate as "true," potentially leading to unintended rewrite rule execution. This vulnerability has a CVSS score of 6.3 (Medium), indicating it can be exploited remotely with low complexity and user privileges, potentially impacting confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage. Users are advised to upgrade to Apache HTTP Server version 2.4.65 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.64CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.64:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP Device Manager Vulnerability Update (5.0.16)
Mar 9, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: Apache HTTP Server logic flaw
Jul 23, 2025Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64
Jul 8, 2025Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project