CVE-2025-23048

Source
https://cve.org/CVERecord?id=CVE-2025-23048
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-23048.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-23048
Aliases
Downstream
ALPINE (1)
AZL (2)
BELL (1)
CGA (2)
CLSA (5)
DEBIAN (1)
MGASA (1)
MINI (1)
OESA (6)
openSUSE (2)
RHSA (11)
RLSA (3)
ROOT (1)
SUSE (7)
UBUNTU (1)
Related
Published
2025-07-10T16:56:53Z
Modified
2026-09-23T03:45:12Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Apache HTTP Server: mod_ssl access control bypass with session resumption
Details

In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption.

Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.

Database specific
{
    "cna_assigner":  "apache",
    "cwe_ids":  [
        "CWE-284"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/23xxx/CVE-2025-23048.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "2.4.35"
                },
                {
                    "last_affected":  "2.4.63"
                }
            ],
            "source":  "AFFECTED_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "introduced":  "2.4.35"
                }
            ],
            "source":  "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/apache/httpd

Affected ranges

Type
GIT
Repo
https://github.com/apache/httpd
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "2.4.35"
        },
        {
            "fixed":  "2.4.64"
        }
    ],
    "source":  "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-23048.json"