Release of Apache HTTP Server 2.4.66 addressing 5 vulnerabilities
The release of the Apache HTTP Server 2.4.66 has been announced, which fixes 5 vulnerabilities and includes several dozen changes. The addressed vulnerabilities (the first 2 have a moderate risk level, while the others are low): CVE-2025-66200 — the organization of running CGI scripts under another user in configurations with mod_userdir and suexec via manipulation of the 'RequestHeader' directive in the .htaccess file (if its use is allowed in .htaccess). CVE-2025-59775 — […]
