CVE-2025-29987 · Apache
Apache HTTP Server Path Traversal
- Severity:
- High
- CVSS:
- 8.6
- Published:
- May 11, 2025
Summary
Improper normalisation of encoded path segments allows an attacker to read files outside the configured web root.
Affected products
Apache HTTP Server 2.4.x builds prior to the fixed release.
Impact
Disclosure of configuration files, credentials, and application source code.
Recommended action
Upgrade to the patched release and audit access logs for encoded traversal attempts.
Need clarity fast?
Whether you're a website owner, product team, or business leader, we'll expertly help you investigate, assess, and secure what matters most.
- 24/7 secure intake
- Confidential and discreet
- Rapid expert response
We respect your privacy. No spam. Ever. Or email support@techforensiq.com