The mod_rewrite escaping flaw: a rewrite rule that maps a url somewhere you did not intend
Improper escaping of output in mod_rewrite lets a crafted URL be mapped to a filesystem path the rule was never meant to reach. CISA added it to the Known Exploited catalogue in May 2025.
A fixed package version is available on 6 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.
What it actually is
mod_rewrite substitutes parts of a request into a target path without escaping them correctly. A request built to exploit that can be rewritten to a location outside the intended tree, which depending on the rules in force means reading source that should not be served, or executing it.
What an attacker gets: Disclosure of files outside the web root, and in some configurations code execution. What exactly depends entirely on the rewrite rules on the server.
When it applies to you, and when it does not
An old package version and a real exposure are different things. These are the conditions this one needs.
- It needs mod_rewrite enabled and rules that substitute request data into a filesystem target. A server with mod_rewrite loaded but no such rule is not exposed.
- Hosting panels generate rewrite rules constantly, which is why this matters more on a cPanel or Plesk box than on a hand-configured one.
- The fix changed behaviour for some rules. Apache documented that rules relying on the old, unescaped substitution may need adjusting, so this is one to read about before a blind upgrade of a busy server.
Check your own server
apache2ctl -M 2>/dev/null | grep -i rewrite || httpd -M 2>/dev/null | grep -i rewriteNothing printed means mod_rewrite is not loaded and the affected code never runs.
Fixed package version, per distribution
From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.
| Release | Source package | State | Fixed in |
|---|---|---|---|
| Ubuntu 22.04 LTS | apache2 | Fixed | 2.4.52-1ubuntu4.10 |
| Ubuntu 24.04 LTS | apache2 | Fixed | 2.4.58-1ubuntu8.2 |
| Debian 12 (bookworm) | apache2 | Fixed | 2.4.61-1~deb12u1 |
| Debian 13 (trixie) | apache2 | Fixed | 2.4.60-1 |
| Rocky Linux 9 | httpd | Fixed | 0:2.4.57-11.el9_4 |
| AlmaLinux 9 | httpd | Fixed | 2.4.57-11.el9_4 |
Install the fix with apt update && apt install --only-upgrade apache2 apache2-bin on Debian and Ubuntu, or dnf update httpd httpd-core on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.
What SecAI has recorded about it
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected. Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.
Recorded from nvd. Its weakness class is CWE-116, from NVD.
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://security.netapp.com/advisory/ntap-20240712-0001/
- http://www.openwall.com/lists/oss-security/2024/07/01/8
- https://github.com/apache/httpd/commit/9a6157d1e2f7ab15963020381054b48782bc18cf
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0018
Read next
Check whether this vulnerability affects your Linux server
One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2024-38475 included. It changes nothing.