Bug 2419139 (CVE-2025-65082)

Summary: CVE-2025-65082 httpd: Apache HTTP Server: CGI environment variable override
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: csutherl, giboye6264, jclere, pjindal, plodge, szappis, vchlup
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A configuration override flaw has been discovered in the apache HTTP server. Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2420214, 2420215    
Bug Blocks:    

Description OSIDB Bzimport 2025-12-05 11:01:16 UTC
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.

This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.

Users are recommended to upgrade to version 2.4.66 which fixes the issue.

Comment 2 errata-xmlrpc 2025-12-22 01:23:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:23732 https://access.redhat.com/errata/RHSA-2025:23732

Comment 3 errata-xmlrpc 2025-12-22 16:50:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:23932 https://access.redhat.com/errata/RHSA-2025:23932

Comment 4 errata-xmlrpc 2025-12-22 18:36:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:23919 https://access.redhat.com/errata/RHSA-2025:23919

Comment 5 tutorframe 2025-12-30 08:11:23 UTC
The following items have addressed this issue:  https://access.redhat.com/errata/RHSA-2025:23919 https://soflowheelie-life.github.io

Comment 6 errata-xmlrpc 2026-02-23 19:17:12 UTC
This issue has been addressed in the following products:

  JBoss Core Services on RHEL 7
  JBoss Core Services for RHEL 8

Via RHSA-2026:2994 https://access.redhat.com/errata/RHSA-2026:2994

Comment 7 errata-xmlrpc 2026-02-23 19:19:25 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Core Services 2.4.62.SP3

Via RHSA-2026:2995 https://access.redhat.com/errata/RHSA-2026:2995