
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59775 is a Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows that allows unauthenticated remote attackers to leak NTLM hashes to an attacker-controlled server. The vulnerability affects Apache HTTP Server versions 2.4.0 through 2.4.65 and is only exploitable when both AllowEncodedSlashes On and MergeSlashes Off directives are configured. It was reported on 2025-09-10 by Orange Tsai (@orange_8361) from DEVCORE, fixed on 2025-12-01, and publicly disclosed on 2025-12-04/05. It carries a CVSS v3.1 base score of 7.5 (High) (oss-security, Apache Advisory).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and stems from improper handling of encoded URL paths on Windows when AllowEncodedSlashes On and MergeSlashes Off are both enabled. Under these conditions, an attacker can craft malicious HTTP requests containing UNC-style paths (e.g., \\attacker-server\share) that cause the Apache HTTP Server process to initiate an outbound SMB/NTLM authentication attempt to an attacker-controlled host, leaking the server's NTLM credentials in the process. The attack requires no authentication and no user interaction, but does require the specific non-default Apache configuration combination to be present (oss-security, Apache Advisory).
Successful exploitation results in the disclosure of NTLM hashes from the Windows account running the Apache HTTP Server process to an attacker-controlled server. These captured NTLM hashes can subsequently be cracked offline to recover plaintext credentials or used directly in NTLM relay attacks, potentially enabling lateral movement within the network. The confidentiality impact is rated High, with no direct integrity or availability impact from the vulnerability itself (oss-security, Feedly).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The vulnerability requires no authentication and no user interaction, but is constrained to Windows deployments with a specific non-default Apache configuration (AllowEncodedSlashes On and MergeSlashes Off), which limits the attack surface. The EPSS score is approximately 0.017% (0.000170), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It was discovered by Orange Tsai of DEVCORE (oss-security, Feedly).
AllowEncodedSlashes On and MergeSlashes Off are active, which may be inferred from how the server handles encoded slash characters in URLs.%5C%5Cattacker-ip%5Cshare) that, when decoded by Apache under the vulnerable configuration, causes the server to initiate an outbound SMB connection to an attacker-controlled host.ntlmrelayx) on the attacker-controlled server to capture the NTLM authentication attempt from the Apache server process.%5C%5C, %2F%2F) or UNC-style path patterns in request URIs; Windows Security Event Log entries (Event ID 4624/4625) showing NTLM authentication attempts to external hosts from the Apache service account.httpd.exe process initiating unexpected network connections to external SMB endpoints.Upgrade Apache HTTP Server to version 2.4.66 or later, which contains the official fix for this vulnerability (Apache Advisory). As a configuration-based workaround, review and disable the AllowEncodedSlashes On and MergeSlashes Off directives if they are not required by the application, as the vulnerability only exists when both are enabled simultaneously. Additionally, restrict outbound SMB traffic (TCP port 445) from the Apache server host using host-based or network firewalls to prevent NTLM hash leakage even if exploitation is attempted. Apple has also released patches addressing this CVE in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4 (Apple macOS Sequoia, Apple macOS Sonoma, Apple macOS Tahoe).
The vulnerability was disclosed via the oss-security mailing list by Apache committer Eric Covener, crediting Orange Tsai of DEVCORE as the finder. Security news outlets such as SecurityOnline.info covered the disclosure in the context of the broader Apache HTTP Server 2.4.66 release, which also addressed other vulnerabilities. The community noted that the attack surface is limited by the non-default configuration requirement, moderating the overall severity assessment (oss-security, SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."