Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.63.
Note: The Apache HTTP Server Project will be setting a higher bar for accepting vulnerability reports regarding SSRF via UNC paths.
The server offers limited protection against administrators directing the server to open UNC paths. Windows servers should limit the hosts they will connect over via SMB based on the nature of NTLM authentication.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 8, 2025 | Jul 10, 2025 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 18, 2025 | Jul 10, 2025 |
| Debian | — | Upgrade apache2 | Aug 15, 2025 | Aug 15, 2025 |
| Freebsd | — | Upgrade apache24 | Jul 13, 2025 | Jul 11, 2025 |
| Ibm Http_server | — | Apply IBM HTTP Server version 8.5.5.29 or laterApply IBM HTTP Server Interim Fix PH67153Apply IBM HTTP Server version 9.0.5.25 or later | Mar 25, 2026 | Aug 12, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 11, 2025 | Jul 10, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub