Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-71860.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-71860
Upstream
Published
2025-12-05T14:15:49Z
Modified
2026-04-21T04:36:39.833663Z
Summary
CVE-2025-58098 affecting package httpd for versions less than 2.4.66-1
Details

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and modcgid (but not modcgi) passes the shell-escaped query string to #exec cmd="..." directives.

This issue affects Apache HTTP Server before 2.4.66.

Users are recommended to upgrade to version 2.4.66, which fixes the issue.

References

Affected packages

Azure Linux:3 / httpd

Package

Name
httpd
Purl
pkg:rpm/azure-linux/httpd

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.66-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-71860.json"