CVE-2024-38475

The mod_rewrite escaping flaw: a rewrite rule that maps a url somewhere you did not intend

Improper escaping of output in mod_rewrite lets a crafted URL be mapped to a filesystem path the rule was never meant to reach. CISA added it to the Known Exploited catalogue in May 2025.

Apache HTTP ServerIn CISA’s Known Exploited catalogue since 2025-05-01EPSS 100.0% chance of an attempt in 30 daysCVSS 9.1CWE-116CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

A fixed package version is available on 6 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

mod_rewrite substitutes parts of a request into a target path without escaping them correctly. A request built to exploit that can be rewritten to a location outside the intended tree, which depending on the rules in force means reading source that should not be served, or executing it.

What an attacker gets: Disclosure of files outside the web root, and in some configurations code execution. What exactly depends entirely on the rewrite rules on the server.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • It needs mod_rewrite enabled and rules that substitute request data into a filesystem target. A server with mod_rewrite loaded but no such rule is not exposed.
  • Hosting panels generate rewrite rules constantly, which is why this matters more on a cPanel or Plesk box than on a hand-configured one.
  • The fix changed behaviour for some rules. Apache documented that rules relying on the old, unescaped substitution may need adjusting, so this is one to read about before a blind upgrade of a busy server.

Check your own server

Read-only, changes nothing
apache2ctl -M 2>/dev/null | grep -i rewrite || httpd -M 2>/dev/null | grep -i rewrite

Nothing printed means mod_rewrite is not loaded and the affected code never runs.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSapache2Fixed2.4.52-1ubuntu4.10
Ubuntu 24.04 LTSapache2Fixed2.4.58-1ubuntu8.2
Debian 12 (bookworm)apache2Fixed2.4.61-1~deb12u1
Debian 13 (trixie)apache2Fixed2.4.60-1
Rocky Linux 9httpdFixed0:2.4.57-11.el9_4
AlmaLinux 9httpdFixed2.4.57-11.el9_4

Install the fix with apt update && apt install --only-upgrade apache2 apache2-bin on Debian and Ubuntu, or dnf update httpd httpd-core on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.

Recorded from nvd. Its weakness class is CWE-116, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2024-38475 included. It changes nothing.