Skip to content
Saturday, December 6, 2025
High Published: Dec 05, 2025 Modified: Dec 05, 2025

CVE-2025-59775

7.5 CVSS SCORE
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Share:

Description

Server-Side Request Forgery (SSRF) vulnerability

 in Apache HTTP Server on Windows

with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM
hashes to a malicious server via SSRF and malicious requests or content

Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS Vector Details

Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None

Weaknesses (CWE)

  • CWE-918