#VU112728 Cryptographic issues in Apache HTTP Server - CVE-2025-49812
Published: July 10, 2025 / Updated: July 10, 2025
Apache HTTP Server
Apache Foundation
Description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to he way certain mod_ssl configurations handle TLS upgrades. A remote attacker can launch an HTTP desynchronisation attack, which allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade.
Note, only configurations using "SSLEngine optional" to enable TLS upgrades are affected.