CVE-2025-54090

NameCVE-2025-54090
DescriptionA bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache2 (PTS)bullseye2.4.62-1~deb11u1vulnerable
bullseye (security)2.4.62-1~deb11u2vulnerable
bookworm, bookworm (security)2.4.62-1~deb12u2vulnerable
trixie2.4.64-1vulnerable
sid2.4.65-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache2source(unstable)2.4.65-1

Notes

https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2025-54090
Fixed by: https://github.com/apache/httpd/commit/8abb3d06b23975705ebcf4bf4476464fd0b9bd0b

Search for package or bug name: Reporting problems