Loading HuntDB...

GHSA-2qfr-q5v6-m43q

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations.

In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files.

Related CVEs

Key Information

GHSA ID
GHSA-2qfr-q5v6-m43q
Published
July 10, 2025 6:31 PM
Last Modified
July 15, 2025 9:31 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 9, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.