CVE-2025-66200
Publication date 5 December 2025
Last updated 19 January 2026
Ubuntu priority
Cvss 3 Severity Score
Description
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| apache2 | 25.10 questing |
Fixed 2.4.64-1ubuntu3.2
|
| 24.04 LTS noble |
Fixed 2.4.58-1ubuntu8.10
|
|
| 22.04 LTS jammy |
Fixed 2.4.52-1ubuntu4.18
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | Low |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | Low |
| Availability impact | Low |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
References
Related Ubuntu Security Notices (USN)
- USN-7968-1
- Apache HTTP Server vulnerabilities
- 19 January 2026