Apache HTTP Server CGI Environment Variable Override Vulnerability

Vulnerability

A vulnerability exists in Apache HTTP Server versions 2.4.0 through 2.4.65, allowing environment variables set via the Apache configuration to unexpectedly override variables calculated by the server for CGI programs. This improper neutralization of escape, meta, or control sequences could lead to unintended behavior in CGI applications.

Impact

Exploitation of this vulnerability could cause CGI programs to behave unexpectedly, potentially leading to unauthorized actions or information disclosure.

Remediation

Users are advised to upgrade to Apache HTTP Server version 2.4.66, which addresses this vulnerability.

Added: Dec 5, 2025, 11:18 AM
Updated: Dec 5, 2025, 11:18 AM

Vulnerability Rating

Custom Algorithm
spread
9.4
impact
0.6
exploitability
7.6
remediation
7.7
relevance
1.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.