Junglewise Threat Intelligence

CVE-2025-59775: Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off all

CVE-2025-59775 · Severity: high · CVSS 7.5 · Published 2025-12-05

Technologies: Apache HTTP Server. Vendors: Apache.

Executive brief

Server-Side Request Forgery (SSRF) vulnerability

in Apache HTTP Server on Windows

with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content

Users are recommended to upgrade to version 2.4.66, which fixes the issue.

Affected products

  • Apache HTTP Server

Related threats