Server-Side Request Forgery (SSRF) in Apache HTTP Server - CVE-2025-59775

 

Server-Side Request Forgery (SSRF) in Apache HTTP Server - CVE-2025-59775

Published: December 4, 2025 / Updated: December 5, 2025


Vulnerability identifier: #VU119148
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-59775
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input when AllowEncodedSlashes is "On" and MergeSlashes is "Off". A remote attacker can send a specially crafted HTTP request and force the web server into leaking NTLM hashes. 

Note, the vulnerability affects Windows installations only. 


Affected software

Apache HTTP Server
IBM HTTP Server
Gentoo Linux
macOS
Oracle Solaris
WebSphere Remote Server
IBM Rational ClearCase
IBM Rational ClearQuest
Oracle HTTP Server
IBM Business Automation Workflow
IBM Cloud Object Storage Systems
DevOps Code ClearCase
IBM OpenPages with Watson
www-servers/apache

How to mitigate CVE-2025-59775

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.66
macOS - addressed in versions 14.8.5 23J423, 15.7.5 24G624, 26.4 25E246
www-servers/apache - update to 2.4.68
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
IBM HTTP Server - addressed in versions 8.5.5.29, 9.0.5.27
IBM OpenPages with Watson - update to 9.0.5.26
Oracle Solaris - addressed in versions 11.3 ESU 36.35, 11.4 SRU 89

External References

Related Security Bulletins