Vulnerability

CVE-2025-23048

CRITICAL 9.1

CVE-2025-23048 is a critical-severity vulnerability (CVSS v3.1 9.1). As of 2026-10-05, 154 105 hosts in our data show software it affects on an open port in at least 15 countries.

In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.

Published
2025-07-10
Last modified
2025-11-04
CVSS score
9.1 CVSS v3.1
CVSS vector (v3.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploit likelihood (EPSS)
Not scored

Exposure in our data

154 105 hosts

Hosts whose banner shows an affected software version on a port open at their latest check.

Not counted: 22 574 hosts with this CVE only from an older observation.

Counted 2026-10-05 02:21 UTC

By country

Germany DE39 127
United States US16 594
France FR15 336
Netherlands NL14 002
United Kingdom GB13 009
Finland FI5 459
Italy IT4 984
Poland PL4 424
Ireland IE3 507
Spain ES3 235
Czechia CZ2 908
Lithuania LT2 302
Sweden SE2 066
Japan JP1 742
India IN1 698

Affected software seen

http_server 2.4.5841 693
http_server 2.4.5228 853
http_server 2.4.4120 576
http_server 2.4.6218 188
http_server 2.4.379 633
http_server 2.4.596 124
http_server 2.4.385 742
http_server 2.4.573 342
http_server 2.4.543 314
http_server 2.4.633 167
http_server 2.4.562 595
http_server 2.4.462 251