CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF
802.1X. An authentication issue was addressed with improved state management.
Other sources
Accounts. An authorization issue was addressed with improved state management.
— Apple
Admin Framework. A path handling issue was addressed with improved validation.
— Apple
Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF
— Microsoft
apache. This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
— Apple
Server-Side Request Forgery (SSRF) vulnerability
in Apache HTTP Server on Windows
with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.7.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.8.5 - Upgrade
Upgrade
apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.66Patch CVE-2025-59775 - Configuration
Because the issue can allow NTLM leakage when 'AllowEncodedSlashes On' and 'MergeSlashes Off' are used together, review your Apache Windows configuration and set these options away from the vulnerable combination described as 'AllowEncodedSlashes On' with 'MergeSlashes Off'.
Apache HTTP Server on Windows AllowEncodedSlashes = On
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28865
- CVE-2026-28877
- CVE-2026-28823
- CVE-2025-55753
- CVE-2025-58098
- CVE-2025-59775
- CVE-2025-65082
- CVE-2025-66200
- CVE-2026-28824
- CVE-2026-20696
- CVE-2026-20699
- CVE-2026-20684
- CVE-2026-20633
- CVE-2026-28910
- CVE-2026-28879
- CVE-2026-28822
- CVE-2026-28894
- CVE-2026-28866
- CVE-2026-20690
- CVE-2026-28821
- CVE-2026-28838
- CVE-2026-20679
- CVE-2026-28886
- CVE-2026-28878
- CVE-2026-28888
- CVE-2026-28893
- CVE-2025-14524
- CVE-2026-28876
- CVE-2026-28892
- CVE-2026-28926
- CVE-2026-28832
- CVE-2026-28870
- CVE-2026-28834
- CVE-2026-28881
- CVE-2026-28880
- CVE-2026-28833
- CVE-2025-64505
- CVE-2026-28842
- CVE-2026-28841
- CVE-2026-28868
- CVE-2026-28867
- CVE-2026-20698
- CVE-2026-20695
- CVE-2026-20687
- CVE-2026-28845
- CVE-2026-28882
- CVE-2026-20607
- CVE-2026-20692
- CVE-2026-20694
- CVE-2026-20632
- CVE-2026-28839
- CVE-2026-20701
- CVE-2026-28891
- CVE-2026-28827
- CVE-2026-28816
- CVE-2026-28826
- CVE-2026-20631
- CVE-2026-20693
- CVE-2026-28840
- CVE-2026-28862
- CVE-2026-28896
- CVE-2026-28831
- CVE-2026-28817
- CVE-2026-20688
- CVE-2026-28864
- CVE-2026-28830
- CVE-2026-28860
- CVE-2026-28835
- CVE-2026-28825
- CVE-2026-28818
- CVE-2026-20697
- CVE-2026-28820
- CVE-2026-28837
- CVE-2026-28844
- CVE-2026-28828
- CVE-2026-28852
- CVE-2026-20657
- CVE-2026-28829
- CVE-2026-20665
- CVE-2026-20643
- CVE-2026-28871
- CVE-2026-20664
- CVE-2026-28857
- CVE-2026-28861
- CVE-2026-28859
- CVE-2026-20691
- CVE-2026-20637
- CVE-2026-20660
- CVE-2026-20639
- CVE-2026-20668
- CVE-2026-20651
Frequently Asked Questions
What is the severity of CVE-2025-59775?
CVE-2025-59775 is classified as a high severity Server-Side Request Forgery (SSRF) vulnerability.
How do I fix CVE-2025-59775?
To fix CVE-2025-59775, upgrade your Apache HTTP Server to version 2.4.67 or later.
What versions of Apache HTTP Server are affected by CVE-2025-59775?
CVE-2025-59775 affects Apache HTTP Server versions up to 2.4.66.
What does the vulnerability CVE-2025-59775 allow an attacker to do?
CVE-2025-59775 allows an attacker to potentially leak NTLM hashes to a malicious server via exploited SSRF.
On which platform does CVE-2025-59775 occur?
CVE-2025-59775 occurs specifically on the Windows platform of Apache HTTP Server.