An .htaccess file is configuration written by someone other than the administrator and read on every request. That makes it a security boundary, as CVE-2025-66200 (fixed in 2.4.66), CVE-2026-24072 (2.4.67) and CVE-2026-44119 (2.4.68) showed, and a measurable cost. The examples use a test virtual host on port 8104 with DocumentRoot /var/www/example.