Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-71590.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-71590
Upstream
Published
2025-12-05T11:15:52Z
Modified
2026-04-01T05:21:44.931026Z
Summary
CVE-2025-66200 affecting package httpd for versions less than 2.4.66-1
Details

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.

This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65.

Users are recommended to upgrade to version 2.4.66, which fixes the issue.

References

Affected packages

Azure Linux:2 / httpd

Package

Name
httpd
Purl
pkg:rpm/azure-linux/httpd

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.66-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-71590.json"