CVE-2025-59775

Server-Side Request Forgery (SSRF) vulnerability 

in Apache HTTP Server on Windows 

with AllowEncodedSlashes Onand MergeSlashes Off allows to potentially leak NTLM 
hashes to a malicious server via SSRF and malicious requests or content

Users are recommended to upgrade to version 2.4.66, which fixes the issue.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
apacheCNA
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
apache2
bullseye
2.4.62-1~deb11u1
fixed
bullseye (security)
2.4.65-1~deb11u1
fixed
bookworm
2.4.65-1~deb12u1
fixed
bookworm (security)
2.4.62-1~deb12u2
fixed
trixie
2.4.65-2
fixed
forky
2.4.65-3
fixed
sid
2.4.65-3
fixed