Description

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade.

INFO

Published Date :

2025-07-10T16:58:23.943Z

Last Modified :

2025-11-04T21:11:18.699Z

Source :

apache
AFFECTED PRODUCTS

The following products are affected by CVE-2025-49812 vulnerability.

Vendors Products
Apache
  • Http Server
Apache Software Foundation
  • Apache Http Server

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact