Apache HTTP Server: 'RewriteCond expr' always evaluates to true
Bogdanp
created: July 24, 2025, 4:20 a.m. | updated: July 24, 2025, 7:12 p.m.
*) SECURITY: CVE-2025-54090 : Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64 (cve.mitre.org) A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".
Users are recommended to upgrade to version 2.4.65, which fixes the issue.
Reviewed By: covener, ylavic, gbechis, jorton git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@1927361 13f79535-47bb-0310-9956-ffa450edef68
1 week, 4 days ago: Hacker News: Front Page