HTTP Desynchronisation Vulnerability in Apache HTTP Server by The Apache Software Foundation
CVE-2025-49812

7.4HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 July 2025

What is CVE-2025-49812?

A vulnerability exists in certain configurations of mod_ssl for Apache HTTP Server versions up to 2.4.63, which permits a man-in-the-middle attacker to exploit an HTTP desynchronisation attack. This exploit allows the attacker to hijack an HTTP session by leveraging a TLS upgrade feature. Specifically, configurations utilizing 'SSLEngine optional' to facilitate TLS upgrades are susceptible. Users are strongly advised to upgrade to Apache HTTP Server version 2.4.64 or later, which addresses this vulnerability by removing support for TLS upgrade.

Affected Version(s)

Apache HTTP Server 0 <= 2.4.63

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robert Merget (Technology Innovation Institute)
Nurullah Erinola (Ruhr University Bochum)
Marcel Maehren (Ruhr University Bochum)
Lukas Knittel (Ruhr University Bochum)
Sven Hebrok (Paderborn University)
Marcus Brinkmann (Ruhr University Bochum)
Juraj Somorovsky (Paderborn University)
Jörg Schwenk (Ruhr University Bochum)
.
CVE-2025-49812 : HTTP Desynchronisation Vulnerability in Apache HTTP Server by The Apache Software Foundation