CVE-2025-58098
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and modcgid (but not modcgi) passes the shell-escaped query string to #exec cmd="..." directives.
This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://httpd.apache.org/security/vulnerabilities24.html, http://www.openwall.com/lists/oss-security/2025/12/04/5, https://httpd.apache.org/security/vulnerabilities24.html, http://www.openwall.com/lists/oss-security/2025/12/04/5
