VYPR
Unrated severityNVD Advisory· Published Dec 5, 2025· Updated Feb 26, 2026

Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

CVE-2025-58098

Description

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.

This issue affects Apache HTTP Server before 2.4.66.

Users are recommended to upgrade to version 2.4.66, which fixes the issue.

Affected products

2
  • Range: <=2.4.65
  • Apache Software Foundation/Apache HTTP Serverv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.