Skip to main content
Vulnerability Intelligence
Platform
Solutions
Customers
Resources
Company
Login
Get Demo
Vulnerability Intelligence
SUSE-SU-2026:0020-1
SUSE-SU-2026:0020-1
UNKNOWN
Security update for apache2
Published Jan 5, 2026
Modified 2 weeks ago
Fix available
Details
This update for apache2 fixes the following issues:
CVE-2025-55753: Fixed mod_md (ACME) unintended retry intervals (bsc#1254511)
CVE-2025-65082: Fixed CGI environment variable override (bsc#1254514)
CVE-2025-58098: Fixed Server Side Includes adding query string to #exec cmd=... (bsc#1254512)
CVE-2025-66200: Fixed mod_userdir+suexec bypass via AllowOverride FileInfo (bsc#1254515)
Affected Packages
apache2
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP6
openSUSE Leap 15.6
Fixed in:
2.4.58-150600.5.41.1
apache2-devel
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP6
openSUSE Leap 15.6
Fixed in:
2.4.58-150600.5.41.1
apache2-prefork
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP6
openSUSE Leap 15.6
Fixed in:
2.4.58-150600.5.41.1
apache2-utils
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP6
openSUSE Leap 15.6
Fixed in:
2.4.58-150600.5.41.1
apache2-worker
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP6
openSUSE Leap 15.6
Fixed in:
2.4.58-150600.5.41.1
apache2-event
openSUSE Leap 15.6
Fixed in:
2.4.58-150600.5.41.1
apache2-manual
openSUSE Leap 15.6
Fixed in:
2.4.58-150600.5.41.1
References
REPORT
https://bugzilla.suse.com/1254511
REPORT
https://bugzilla.suse.com/1254512
REPORT
https://bugzilla.suse.com/1254514
REPORT
https://bugzilla.suse.com/1254515
WEB
https://www.suse.com/security/cve/CVE-2025-55753
WEB
https://www.suse.com/security/cve/CVE-2025-58098
WEB
https://www.suse.com/security/cve/CVE-2025-65082
WEB
https://www.suse.com/security/cve/CVE-2025-66200
ADVISORY
https://www.suse.com/support/update/announcement/2026/suse-su-20260020-1/
Upstream
CVE-2025-55753
CVE-2025-58098
CVE-2025-65082
CVE-2025-66200
Related
CVE-2025-55753
CVE-2025-58098
CVE-2025-65082
CVE-2025-66200
Ecosystems
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP6
openSUSE Leap 15.6
Timeline
Published
Jan 5, 2026
Modified
Jan 5, 2026
SUSE-SU-2026:0020-1 | Mondoo Vulnerability Intelligence