CVE-2025-54090
MEDIUMDescription
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| apache | http_server |
References
Frequently Asked Questions
What is CVE-2025-54090? +
How severe is CVE-2025-54090? +
What products are affected by CVE-2025-54090? +
How do I check if I'm vulnerable to CVE-2025-54090? +
Related Vulnerabilities
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.
Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, …
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a …
Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to …
Windows Hyper-V Denial of Service Vulnerability
Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer …