VYPR
Unrated severityNVD Advisory· Published Dec 5, 2025· Updated Dec 5, 2025

Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF

CVE-2025-59775

Description

Server-Side Request Forgery (SSRF) vulnerability

in Apache HTTP Server on Windows

with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content

Users are recommended to upgrade to version 2.4.66, which fixes the issue.

Affected products

2
  • Range: <2.4.66
  • Apache Software Foundation/Apache HTTP Serverv5
    Range: 2.4.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.