HomeDefault status
unaffected
2.4.0 (semver)
affected
Description
Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
2.4.0 (semver)
Timeline
| 2025-09-10: | reported |
| 2025-12-01: | fixed in 2.4.x by r1930166 |
Credits
Orange Tsai (@orange_8361) from DEVCORE
References
www.openwall.com/lists/oss-security/2025/12/04/6
httpd.apache.org/security/vulnerabilities_24.html