#VU119148 Server-Side Request Forgery (SSRF) in Apache HTTP Server - CVE-2025-59775
Published: December 4, 2025 / Updated: December 5, 2025
Apache HTTP Server
Apache Foundation
Description
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input when AllowEncodedSlashes is "On" and MergeSlashes is "Off". A remote attacker can send a specially crafted HTTP request and force the web server into leaking NTLM hashes.
Note, the vulnerability affects Windows installations only.