CVE-2025-58098

CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

Vendor Apache Software Foundation
Product Apache HTTP Server
Weakness CWE-201
Published December 5, 2025
Last update February 26, 2026

CVSS base score

What the vulnerability does

Description

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

Key dates

Disclosure timeline

December 5, 2025 CVE published
February 26, 2026 Record updated