---
id: CVE-2025-59775
title: "Server-Side Request Forgery (SSRF) vulnerability \n\n\_in Apache HTTP Server on Windows \n\nwith AllowEncodedSlashes On\_and MergeSlashes Off\_ allows to potentially leak NTLM \nhashes to a malicious server via SSRF and malicious requests or con…"
summary: "Server-Side Request Forgery (SSRF) vulnerability \n\n\_in Apache HTTP Server on Windows \n\nwith AllowEncodedSlashes On\_and MergeSlashes Off\_ allows to potentially leak NTLM \nhashes to a malicious server via SSRF and malicious requests or con…"
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: apache
product: http_server
affected:
  - 'http_server >= 2.4.0, < 2.4.66'
patched:
  - http_server 2.4.66
published: '2025-12-05'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59775'
references:
  - url: 'https://httpd.apache.org/security/vulnerabilities_24.html'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2025/12/04/6'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00821
epssPercentile: 0.55489
ingestedAt: '2026-09-25T23:21:16.892Z'
---

## Overview

Server-Side Request Forgery (SSRF) vulnerability 

 in Apache HTTP Server on Windows 

with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM 
hashes to a malicious server via SSRF and malicious requests or content

Users are recommended to upgrade to version 2.4.66, which fixes the issue.

## Affected

- `http_server >= 2.4.0, < 2.4.66`

## Remediation

Upgrade past the affected range:

- `http_server 2.4.66`
