high CVSS 8.3

CVE-2025-58098·Apache vulnerability

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

Severity
high
Software
Apache
Fixed in
2.4.66
Published
2025-12-05

Affected versions

Until: 2.4.66

Fixed in: 2.4.66

How to fix this CVE

Upgrade Apache HTTP Server to version 2.4.66 or later to patch the Server Side Includes (SSI) command injection vulnerability. This fix prevents improper shell escaping of query strings when using mod_cgid with #exec directives, which could allow authenticated users to execute arbitrary shell commands on the server. If you cannot upgrade immediately, disable Server Side Includes or switch from mod_cgid to mod_cgi as a temporary mitigation.

sudo dnf update -y httpd httpd-core httpd-devel

Defensia detects this vulnerability

What an exploitation attempt looks like

Sample log line indicative of exploitation attempts:

POST|GET.*\?.*exec\s+cmd=|SSI.*#exec.*cmd=.*\$\(.*\)|query string containing shell metacharacters passed to #exec directive in .shtml file processing

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Block HTTP requests to .shtml files containing query strings with shell metacharacters (;, |, &, $, `, \n, \r) or the pattern 'exec cmd=' in the query string. Implement strict input validation on CGI parameters and restrict execution of SSI directives with external command invocation.

How to check if you are affected

  1. Check your Apache version with: apache2ctl -v (or httpd -v on RHEL/CentOS) and confirm if it is 2.4.66 or later
  2. Verify if Server Side Includes are enabled by checking httpd.conf for 'AddType text/html .shtml' and 'AddOutputFilter INCLUDES .shtml' directives
  3. Confirm mod_cgid is loaded instead of mod_cgi by running: apache2ctl -M | grep cgid (should show cgid_module if vulnerable configuration is present)
  4. Review Apache error and access logs for patterns like '?exec cmd=' in query strings combined with .shtml requests, indicating potential exploitation attempts

FAQ

What is CVE-2025-58098?

This vulnerability allows authenticated users to execute arbitrary shell commands on Apache servers running version 2.4.65 or earlier with Server Side Includes enabled and mod_cgid loaded, due to improper shell escaping of query string parameters in #exec directives.

Is CVE-2025-58098 being actively exploited?

No, there are currently no reports of active exploitation or public exploits available for this vulnerability.

What versions of Apache are affected by CVE-2025-58098?

All versions up to and including Apache 2.4.65 are affected; version 2.4.66 and later contain the patch.

How do I check if my server is vulnerable to CVE-2025-58098?

Run 'apache2ctl -v' to check the version, then verify SSI is enabled with 'grep -E "AddOutputFilter INCLUDES" /etc/apache2/httpd.conf' and confirm mod_cgid is loaded with 'apache2ctl -M | grep cgid_module' — if all three conditions are true, your server is vulnerable.

Does Defensia detect CVE-2025-58098?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2025-58098 will appear in your dashboard with remediation steps.

Related Apache CVEs

CVE-2024-38476CVSS 9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CVE-2024-38474CVSS 9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
CVE-2025-23048CVSS 9.1In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.
CVE-2024-38475CVSS 9.1Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.
CVE-2024-38473CVSS 8.1Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-58098. Free for 1 server.

Get started free