Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:23732 https://access.redhat.com/errata/RHSA-2025:23732
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:23932 https://access.redhat.com/errata/RHSA-2025:23932
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:23919 https://access.redhat.com/errata/RHSA-2025:23919
The following items have addressed this issue: https://access.redhat.com/errata/RHSA-2025:23919 https://soflowheelie-life.github.io
This issue has been addressed in the following products: JBoss Core Services on RHEL 7 JBoss Core Services for RHEL 8 Via RHSA-2026:2994 https://access.redhat.com/errata/RHSA-2026:2994
This issue has been addressed in the following products: Red Hat JBoss Core Services 2.4.62.SP3 Via RHSA-2026:2995 https://access.redhat.com/errata/RHSA-2026:2995