CVE-2025-29987 · Apache

Apache HTTP Server Path Traversal

Severity:
High
CVSS:
8.6
Published:
May 11, 2025

Summary

Improper normalisation of encoded path segments allows an attacker to read files outside the configured web root.

Affected products

Apache HTTP Server 2.4.x builds prior to the fixed release.

Impact

Disclosure of configuration files, credentials, and application source code.

Recommended action

Upgrade to the patched release and audit access logs for encoded traversal attempts.

Back to vulnerability database

Need clarity fast?

Whether you're a website owner, product team, or business leader, we'll expertly help you investigate, assess, and secure what matters most.

  • 24/7 secure intake
  • Confidential and discreet
  • Rapid expert response

We respect your privacy. No spam. Ever. Or email support@techforensiq.com