Software 43918 Published by

Apache HTTP Webserver 2.4.65 fixes security bug CVE-2025-54090, causing "RewriteCond expr" tests to evaluate as true in 2.4.64. Users are recommended to upgrade to version 2.4.65.



Apache/httpd Release 2.4.65

Changes with Apache 2.4.65

*) SECURITY: CVE-2025-54090: Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64 (cve.mitre.org)
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".
Users are recommended to upgrade to version 2.4.65, which fixes the issue.

Release 2.4.65 · apache/httpd