Vulnerability
CVE-2025-23048
CVE-2025-23048 is a critical-severity vulnerability (CVSS v3.1 9.1). As of 2026-10-05, 154 105 hosts in our data show software it affects on an open port in at least 15 countries.
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.
- Published
- 2025-07-10
- Last modified
- 2025-11-04
- CVSS score
- 9.1 CVSS v3.1
- CVSS vector (v3.1)
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Exploit likelihood (EPSS)
- Not scored
Exposure in our data
154 105 hosts
Hosts whose banner shows an affected software version on a port open at their latest check.
Not counted: 22 574 hosts with this CVE only from an older observation.
Counted 2026-10-05 02:21 UTC
By country
| Germany DE | 39 127 |
| United States US | 16 594 |
| France FR | 15 336 |
| Netherlands NL | 14 002 |
| United Kingdom GB | 13 009 |
| Finland FI | 5 459 |
| Italy IT | 4 984 |
| Poland PL | 4 424 |
| Ireland IE | 3 507 |
| Spain ES | 3 235 |
| Czechia CZ | 2 908 |
| Lithuania LT | 2 302 |
| Sweden SE | 2 066 |
| Japan JP | 1 742 |
| India IN | 1 698 |
Affected software seen
| http_server 2.4.58 | 41 693 |
| http_server 2.4.52 | 28 853 |
| http_server 2.4.41 | 20 576 |
| http_server 2.4.62 | 18 188 |
| http_server 2.4.37 | 9 633 |
| http_server 2.4.59 | 6 124 |
| http_server 2.4.38 | 5 742 |
| http_server 2.4.57 | 3 342 |
| http_server 2.4.54 | 3 314 |
| http_server 2.4.63 | 3 167 |
| http_server 2.4.56 | 2 595 |
| http_server 2.4.46 | 2 251 |