Software 43948 Published by

Apache HTTP Webserver 2.4.65 fixes security bug CVE-2025-54090, causing "RewriteCond expr" tests to evaluate as true in 2.4.64. Users are recommended to upgrade to version 2.4.65.



Apache/httpd Release 2.4.65

Changes with Apache 2.4.65

*) SECURITY: CVE-2025-54090: Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64 (cve.mitre.org)
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".
Users are recommended to upgrade to version 2.4.65, which fixes the issue.

Release 2.4.65 ยท apache/httpd