mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.
This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
References
| Link | Resource |
|---|---|
| https://httpd.apache.org/security/vulnerabilities_24.html | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/12/04/8 | Issue Tracking Third Party Advisory |
Configurations
History
10 Dec 2025, 16:39
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | |
| First Time |
Apache http Server
Apache |
|
| References | () https://httpd.apache.org/security/vulnerabilities_24.html - Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2025/12/04/8 - Issue Tracking, Third Party Advisory |
05 Dec 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| CWE | CWE-288 |
05 Dec 2025, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-05 11:15
Updated : 2025-12-10 16:39
NVD link : CVE-2025-66200
Mitre link : CVE-2025-66200
CVE.ORG link : CVE-2025-66200
JSON object : View
Products Affected
apache
- http_server
CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
