Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.63.
Note: The Apache HTTP Server Project will be setting a higher bar for accepting vulnerability reports regarding SSRF via UNC paths.
The server offers limited protection against administrators directing the server to open UNC paths. Windows servers should limit the hosts they will connect over via SMB based on the nature of NTLM authentication.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-apache2 | Aug 8, 2025 | Jul 10, 2025 | |
| Apache Httpd | apache-httpd-upgrade-latest | Jul 18, 2025 | Jul 10, 2025 | |
| Debian | debian-upgrade-apache2 | Aug 15, 2025 | Aug 15, 2025 | |
| Freebsd | freebsd-upgrade-package-apache24 | Jul 13, 2025 | Jul 11, 2025 | |
| Ibm Http_server | ibm-http_server-apply-interim-fix-ph67153-for-8_5ibm-http_server-apply-interim-fix-ph67153-for-9_0ibm-http_server-apply-fix-pack-8_5_5_29ibm-http_server-apply-fix-pack-9_0_5_25 | Mar 25, 2026 | Aug 12, 2025 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Aug 11, 2025 | Jul 10, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub