CVE-2025-49812

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

History

29 Jul 2025, 15:09

Type Values Removed Values Added
CPE cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
First Time Apache
Apache http Server
References () https://httpd.apache.org/security/vulnerabilities_24.html - () https://httpd.apache.org/security/vulnerabilities_24.html - Vendor Advisory

15 Jul 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-10 17:15

Updated : 2025-07-29 15:09


NVD link : CVE-2025-49812

Mitre link : CVE-2025-49812

CVE.ORG link : CVE-2025-49812


JSON object : View

Products Affected

apache

  • http_server
CWE
CWE-287

Improper Authentication