CVE-2025-65082 is a medium-severity vulnerability affecting Apache HTTP Server versions 2.4.0 through 2.4.65. It involves improper neutralization of escape sequences, allowing environment variables set in the Apache configuration to unexpectedly override server-calculated variables for CGI programs. The vulnerability has a CVSS score of 6.5, indicating low confidentiality and integrity impact, but no availability impact. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has garnered some community discussion and media coverage. Users are advised to upgrade to version 2.4.66 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.0, <= 2.4.65CPE match | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
>= 2.4.0, < 2.4.66CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server vulnerabilities
May 28, 2026HP Device Manager Vulnerability Update (5.0.16)
Mar 9, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025Apache HTTP Server: CGI environment variable override
Dec 9, 2025httpd: Apache HTTP Server: CGI environment variable override
Dec 5, 2025About the security content of macOS Tahoe 26.4 - Apple Support
About the security content of macOS Sequoia 15.7.5 - Apple Support
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
About the security content of macOS Sonoma 14.8.5 - Apple Support