HTTP Desynchronisation Vulnerability in Apache HTTP Server by The Apache Software Foundation
CVE-2025-49812
What is CVE-2025-49812?
A vulnerability exists in certain configurations of mod_ssl for Apache HTTP Server versions up to 2.4.63, which permits a man-in-the-middle attacker to exploit an HTTP desynchronisation attack. This exploit allows the attacker to hijack an HTTP session by leveraging a TLS upgrade feature. Specifically, configurations utilizing 'SSLEngine optional' to facilitate TLS upgrades are susceptible. Users are strongly advised to upgrade to Apache HTTP Server version 2.4.64 or later, which addresses this vulnerability by removing support for TLS upgrade.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache HTTP Server 0 <= 2.4.63
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved