Skip to content
Fedora 43: Critical Security Update for httpd CVE-2025

Fedora 43: Critical Security Update for httpd CVE-2025

Linuxsecurity •LinuxSecurity Advisories • December 11, 2025

The Apache HTTP Server is a powerful, efficient, and extensible web server. Update Information : version update security update

The Apache HTTP Server is a powerful, efficient, and extensible

version update security update

* Tue Dec 9 2025 Lubo\u0161 Uhliarik - 2.4.66-1 - new version 2.4.66

* Tue Dec 9 2025 Lubo\u0161 Uhliarik - 2.4.66-1 - new version 2.4.66

[ 1 ] Bug #2419768 - httpd-2.4.66 is available [ 2 ] Bug #2420206 - CVE-2025-58098 httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... [fedora-42] [ 3 ] Bug #2420207 - CVE-2025-58098 httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... [fedora-43] [ 4 ] Bug #2420208 - CVE-2025-66200 httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo [fedora-42] [ 5 ] Bug #2420209 - CVE-2025-66200 httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo [fedora-43] [ 6 ] Bug #2420214 - CVE-2025-65082 httpd: Apache HTTP Server: CGI environment variable override [fedora-42] htt... Read the Full Advisory

[ 1 ] Bug #2419768 - httpd-2.4.66 is available [ 2 ] Bug #2420206 - CVE-2025-58098 httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... [fedora-42] [ 3 ] Bug #2420207 - CVE-2025-58098 httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... [fedora-43] [ 4 ] Bug #2420208 - CVE-2025-66200 httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo [fedora-42] [ 5 ] Bug #2420209 - CVE-2025-66200 httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo [fedora-43] [ 6 ] Bug #2420214 - CVE-2025-65082 httpd: Apache HTTP Server: CGI environment variable override [fedora-42] htt...

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9621c19da8' at the command line. For more information, refer to the dnf documentation available at

Extracted Entities