HTTP Desynchronisation Vulnerability in Apache HTTP Server by The Apache Software Foundation
CVE-2025-49812
7.4HIGH
What is CVE-2025-49812?
A vulnerability exists in certain configurations of mod_ssl for Apache HTTP Server versions up to 2.4.63, which permits a man-in-the-middle attacker to exploit an HTTP desynchronisation attack. This exploit allows the attacker to hijack an HTTP session by leveraging a TLS upgrade feature. Specifically, configurations utilizing 'SSLEngine optional' to facilitate TLS upgrades are susceptible. Users are strongly advised to upgrade to Apache HTTP Server version 2.4.64 or later, which addresses this vulnerability by removing support for TLS upgrade.
Affected Version(s)
Apache HTTP Server 0 <= 2.4.63
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Robert Merget (Technology Innovation Institute)
Nurullah Erinola (Ruhr University Bochum)
Marcel Maehren (Ruhr University Bochum)
Lukas Knittel (Ruhr University Bochum)
Sven Hebrok (Paderborn University)
Marcus Brinkmann (Ruhr University Bochum)
Juraj Somorovsky (Paderborn University)
Jörg Schwenk (Ruhr University Bochum)