CVE-2025-49812

Apache HTTP Server: mod_ssl TLS upgrade attack

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade.


We have discovered 1,876,493 live websites that are affected by CVE-2025-49812.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains1,876,493 live websites (68% of Apache install base)
Vulnerable Versions
  • from 0 through 2.4.63
Vulnerable Versions Count115 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Jul 10, 2025
  • Updated - Nov 4, 2025

Credits

  • Robert Merget (Technology Innovation Institute) (finder)
  • Nurullah Erinola (Ruhr University Bochum) (finder)
  • Marcel Maehren (Ruhr University Bochum) (finder)
  • Lukas Knittel (Ruhr University Bochum) (finder)
  • Sven Hebrok (Paderborn University) (finder)
  • Marcus Brinkmann (Ruhr University Bochum) (finder)
  • Juraj Somorovsky (Paderborn University) (finder)
  • Jörg Schwenk (Ruhr University Bochum) (finder)

Website Distribution by Country

Number of websites using CVE-2025-49812
United States497,715 websites



Germany215,128 websites
Taiwan113,513 websites
France107,488 websites
Netherlands84,840 websites
Japan81,709 websites
Russia68,011 websites
Italy58,702 websites
Czech Republic50,498 websites
GB47,854 websites

Website Distribution by TLD

Number of websites using CVE-2025-49812
.com707,713 websites
.de132,057 websites
.org84,356 websites
.net74,542 websites
.nl63,474 websites
.ru59,897 websites
.it51,260 websites
.cz41,964 websites
.fr34,855 websites
.jp32,966 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-49812

Top websites that are affected by CVE-2025-49812. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Singapore***
*************.***.****.****.************.net United States***
*****.***********.com Canada***
*********.net United States***
***.****.us United States*,***
***.*********.com Singapore*,***
*****.*******.com Singapore*,***
******.net Sweden*,***
******************.com United States*,***
****.*********.net GB*,***
See full domain list

FAQ

CVE-2025-49812 is Improper Authentication in Apache
A total of 1,876,493 websites have been identified as vulnerable to CVE-2025-49812, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2025-49812 vulnerability.
Apache versions up to and including 2.4.63 are vulnerable to CVE-2025-49812.