#VU119147 Code injection in Apache HTTP Server - CVE-2025-65082
Published: December 4, 2025 / Updated: December 5, 2025
Apache HTTP Server
Apache Foundation
Description
The vulnerability allows a local user to affect web server behavior.
The vulnerability exists due to improper input validation when handling environment variables set via the Apache configuration. A local user can set specially crafted values that supersede variables calculated by the server for CGI programs.