F5-K000159875: Low severity F5 F5OS-A vulnerability
Published Apr 2, 2026
·Updated
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.
Affected Software
2 affected components
F5 F5OS-A>=1.8.0<=1.8.3, >=1.5.1<=1.5.4
F5 F5OS-C>=1.8.0<=1.8.2, >=1.6.0<=1.6.4
Event History
Apr 2, 2026
Advisory Published
via F5·04:40 PM
Data Sourced
via F5·04:40 PM
DescriptionSeverityWeaknessAffected Software