#VU119146 Input validation error in Apache HTTP Server - CVE-2025-66200
Published: December 4, 2025 / Updated: December 5, 2025
Apache HTTP Server
Apache Foundation
Description
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input when parsing the RequestHeader directive in .htaccess files. A local user can bypass mod_userdir+suexec security measures via AllowOverride FileInfo and run certain CGI scripts under an unexpected userid.