Red Hat published Important security updates for Apache HTTP Server packages across Red Hat Enterprise Linux 8, 9, and 10 and related JBoss Core Services offerings, addressing multiple upstream httpd vulnerabilities. The updates remediate CVE-2025-65082, which can let Apache configuration-set variables unexpectedly override server-calculated CGI environment variables, and CVE-2025-66200, a mod_userdir + suexec bypass in which an attacker able to use the RequestHeader directive in an .htaccess file may cause some CGI scripts to run under an unexpected user ID. Red Hat advisories for RHEL 9 and 10 also include fixes for CVE-2025-58098, where Server Side Includes appends the query string to #exec cmd, while the RHEL 8 httpd:2.4 module update additionally addresses CVE-2025-55753.
The affected Apache HTTP Server ranges extend through 2.4.65, and upstream guidance points users to 2.4.66 for remediation. Red Hat shipped patched builds including httpd-2.4.62-7.el9_7.3 for RHEL 9 and httpd-2.4.63-4.el10_1.3 for RHEL 10, with corresponding package updates across major architectures and lifecycle channels; the RHEL 8 advisory likewise delivers updated httpd, mod_ssl, mod_http2, mod_md, and related components. The fixes were released under advisories RHSA-2025:23732, RHSA-2025:23919, and RHSA-2025:23932.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2025-12-22, Red Hat published RHSA-2025:23932, an Important security advisory for RHEL 10 httpd packages. The update fixes CVE-2025-65082 and CVE-2025-66200, as well as CVE-2025-58098.
On 2025-12-22, Red Hat published RHSA-2025:23919, an Important security advisory for RHEL 9 httpd packages. The advisory fixes Apache HTTP Server vulnerabilities including CVE-2025-65082 and CVE-2025-66200.
On 2025-12-22, Red Hat published RHSA-2025:23732, an Important security advisory for the RHEL 8 httpd:2.4 module. The update fixes CVE-2025-65082 and CVE-2025-66200, along with CVE-2025-55753 and CVE-2025-58098.
Red Hat tracked CVE-2025-65082 as Bugzilla 2419139, covering an Apache HTTP Server CGI environment variable override flaw affecting versions 2.4.0 through 2.4.65. The bug record states version 2.4.66 fixes the issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.