CVE-2025-53020: Apache HTTP Server

High severity, CVSS 7.5. EPSS: 4.9% chance of exploitation in the next 30 days.

Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.

Affected products

  • Apache HTTP Server: from 2.4.17, before 2.4.64 (fixed in 2.4.64)

Published 2025-07-10. Last modified 2026-06-17.