cbcvebase.
CVE-2025-23048
published 2025-07-10

CVE-2025-23048: In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session…

critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.

Affected

7 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.4.35 < 2.4.642.4.64
apache_software_foundationapache_http_server2.4.35 – 2.4.63
debianapache2< apache2 2.4.65-1~deb12u1 (bookworm)apache2 2.4.65-1~deb12u1 (bookworm)
msrcazl3_httpd_2.4.62-1_on_azure_linux_3.0
msrcazl3_httpd_2.4.64-1_on_azure_linux_3.0
msrccbl2_httpd_2.4.62-1_on_cbl_mariner_2.0
msrccbl2_httpd_2.4.64-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL