---
id: CVE-2025-65082
title: >-
  Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in
  Apache HTTP Server through environment variables set via the Apache
  configuration unexpectedly superseding variables calculated by the server for
  CGI programs…
summary: >-
  Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in
  Apache HTTP Server through environment variables set via the Apache
  configuration unexpectedly superseding variables calculated by the server for
  CGI programs…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-150
vendor: apache
product: http_server
affected:
  - 'http_server >= 2.4.0, < 2.4.66'
patched:
  - http_server 2.4.66
published: '2025-12-05'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-65082'
references:
  - url: 'https://httpd.apache.org/security/vulnerabilities_24.html'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2025/12/04/7'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00807
epssPercentile: 0.55021
ingestedAt: '2026-09-25T23:21:16.892Z'
---

## Overview

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.

This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.

Users are recommended to upgrade to version 2.4.66 which fixes the issue.

## Affected

- `http_server >= 2.4.0, < 2.4.66`

## Remediation

Upgrade past the affected range:

- `http_server 2.4.66`
