CVE-2025-49812

HIGH

Apache HTTP Server < 2.4.64 - HTTP Session Hijacking via TLS Upgrade Desynchronization

Title source: llm
STIX 2.1

Description

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade.

Scores

CVSS v3 7.4
EPSS 0.0045
EPSS Percentile 63.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
apache/http_server < 2.4.64
Published Jul 10, 2025
Tracked Since Feb 18, 2026