CVE-2025-23419

TLS Session Resumption Vulnerability

When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key are used and/or the SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache are used in the default server and the default server is performing client certificate authentication.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.


We have discovered 174,929 live websites that are affected by CVE-2025-23419.

Run a Free Instant Scan




Affected Software

Product  Nginx
Category Web Servers
Vulnerable Domains174,929 live websites (5.36% of Nginx install base)
Vulnerable Versions
  • from 0 through 1.11.4
Vulnerable Versions Count112 versions ( 50% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Feb 5, 2025
  • Updated - Nov 3, 2025

Credits

  • Sven Hebrok (finder)
  • Felix Cramer (finder)
  • Tim Storm (finder)
  • Maximilian Radoy (finder)
  • Juraj Somorovsky (finder)

Website Distribution by Country

Number of websites using CVE-2025-23419
United States51,148 websites



China20,458 websites
Russia19,511 websites
Germany14,602 websites
Singapore12,513 websites
France6,133 websites
New Zealand5,089 websites
Ukraine3,545 websites
Hungary3,542 websites
Italy3,114 websites

Website Distribution by TLD

Number of websites using CVE-2025-23419
.com75,797 websites
.ru17,106 websites
.net6,542 websites
.de6,455 websites
.cn5,895 websites
.org5,491 websites
.it2,779 websites
.fr2,517 websites
.com.br2,489 websites
.dk1,562 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-23419

Top websites that are affected by CVE-2025-23419. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.******.org United States***
***.**.**.com China***
**********.com United States***
****.****.******.org United States***
******.org United States*,***
***.*******.com *,***
*********.******.org United States*,***
********.****.******.org United States*,***
***.****.******.org United States*,***
*****.****.******.org United States*,***
See full domain list

FAQ

CVE-2025-23419 is Improper Authentication in Nginx
A total of 174,929 websites have been identified as vulnerable to CVE-2025-23419, based on global website indexing conducted by WebTechSurvey.
The Nginx is affected by the CVE-2025-23419 vulnerability.
Nginx versions up to 1.11.4 are vulnerable to CVE-2025-23419.
CVE-2025-23419 is resolved in version 1.11.4 of Nginx.