AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-23048

CRITICAL · CVSS 9.1 EPSS 0.97%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-07-10 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.1. It affects Apache.

CVE
CVE-2025-23048
Severity
CRITICAL
CVSS
9.1
EPSS
0.97%
Apache

Original NVD Description

In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.

Related CVEs

Other vulnerabilities affecting the same vendor(s)