CVE-2025-53020

L

ate Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

History

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/07/10/10 -

03 Nov 2025, 20:19

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/08/msg00009.html -

29 Jul 2025, 15:08

Type Values Removed Values Added
CPE cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
First Time Apache http Server
Apache
References () https://httpd.apache.org/security/vulnerabilities_24.html - () https://httpd.apache.org/security/vulnerabilities_24.html - Vendor Advisory

15 Jul 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

15 Jul 2025, 13:24

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de liberación tardía de memoria tras el tiempo de vida útil efectivo en el servidor Apache HTTP. Este problema afecta al servidor Apache HTTP desde la versión 2.4.17 hasta la 2.4.63. Se recomienda actualizar a la versión 2.4.64, que soluciona el problema.

10 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-10 17:15

Updated : 2025-11-04 22:16


NVD link : CVE-2025-53020

Mitre link : CVE-2025-53020

CVE.ORG link : CVE-2025-53020


JSON object : View

Products Affected
CWE
CWE-401

Missing Release of Memory after Effective Lifetime