Server-Side Request Forgery (SSRF) in Apache HTTP Server - CVE-2025-59775
Published: December 4, 2025 / Updated: December 5, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input when AllowEncodedSlashes is "On" and MergeSlashes is "Off". A remote attacker can send a specially crafted HTTP request and force the web server into leaking NTLM hashes.
Note, the vulnerability affects Windows installations only.
Affected software
IBM HTTP Server
Gentoo Linux
macOS
Oracle Solaris
WebSphere Remote Server
IBM Rational ClearCase
IBM Rational ClearQuest
Oracle HTTP Server
IBM Business Automation Workflow
IBM Cloud Object Storage Systems
DevOps Code ClearCase
IBM OpenPages with Watson
www-servers/apache
How to mitigate CVE-2025-59775
macOS - addressed in versions 14.8.5 23J423, 15.7.5 24G624, 26.4 25E246
www-servers/apache - update to 2.4.68
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
IBM HTTP Server - addressed in versions 8.5.5.29, 9.0.5.27
IBM OpenPages with Watson - update to 9.0.5.26
Oracle Solaris - addressed in versions 11.3 ESU 36.35, 11.4 SRU 89
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Multiple vulnerabilities in IBM Business Automation Workflow traditional
- Multiple vulnerabilities in IBM HTTP Server
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Multiple vulnerabilities in Oracle Solaris
- Multiple vulnerabilities in IBM DevOps Code ClearCase
- Multiple vulnerabilities in IBM Rational ClearQuest
- Multiple vulnerabilities in IBM OpenPages
- Multiple vulnerabilities in Apple macOS Tahoe
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Oracle HTTP Server
- Multiple vulnerabilities in IBM Cloud Object System
- Gentoo update for Apache HTTPD