High severity7.5NVD Advisory· Published Dec 5, 2025· Updated Jun 17, 2026
CVE-2025-59775
CVE-2025-59775
Description
Server-Side Request Forgery (SSRF) vulnerability
in Apache HTTP Server on Windows
with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5>=2.4.66+ 2 more
- (no CPE)range: >=2.4.66
- cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*range: >=2.4.0,<2.4.66
- (no CPE)range: 2.4.0
- osv-coords2 versions
>= 2.4.0, < 2.4.66+ 1 more
- (no CPE)range: >= 2.4.0, < 2.4.66
- (no CPE)range: < 2.4.66-1.1
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2025/12/04/6nvdIssue TrackingThird Party Advisory
- httpd.apache.org/security/vulnerabilities_24.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.