In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade.
We have discovered 1,876,493 live websites that are affected by CVE-2025-49812.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 1,876,493 live websites (68% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 115 versions ( 97% of all versions) |
| 497,715 websites | |
| 215,128 websites | |
| 113,513 websites | |
| 107,488 websites | |
| 84,840 websites | |
| 81,709 websites | |
| 68,011 websites | |
| 58,702 websites | |
| 50,498 websites | |
| 47,854 websites |
| .com | 707,713 websites |
| .de | 132,057 websites |
| .org | 84,356 websites |
| .net | 74,542 websites |
| .nl | 63,474 websites |
| .ru | 59,897 websites |
| .it | 51,260 websites |
| .cz | 41,964 websites |
| .fr | 34,855 websites |
| .jp | 32,966 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *** | ||
| *************.***.****.****.************.net | *** | ||
| *****.***********.com | *** | ||
| *********.net | *** | ||
| ***.****.us | *,*** | ||
| ***.*********.com | *,*** | ||
| *****.*******.com | *,*** | ||
| ******.net | *,*** | ||
| ******************.com | *,*** | ||
| ****.*********.net | *,*** |
FAQ