Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:23732 https://access.redhat.com/errata/RHSA-2025:23732
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:23932 https://access.redhat.com/errata/RHSA-2025:23932
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:23919 https://access.redhat.com/errata/RHSA-2025:23919
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:0009 https://access.redhat.com/errata/RHSA-2026:0009
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:0010 https://access.redhat.com/errata/RHSA-2026:0010
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:0011 https://access.redhat.com/errata/RHSA-2026:0011
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:0012 https://access.redhat.com/errata/RHSA-2026:0012
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION Via RHSA-2026:0074 https://access.redhat.com/errata/RHSA-2026:0074
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:0075 https://access.redhat.com/errata/RHSA-2026:0075
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:0095 https://access.redhat.com/errata/RHSA-2026:0095
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:0090 https://access.redhat.com/errata/RHSA-2026:0090
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:0139 https://access.redhat.com/errata/RHSA-2026:0139
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:0141 https://access.redhat.com/errata/RHSA-2026:0141
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:0171 https://access.redhat.com/errata/RHSA-2026:0171